Lucy Mobile App Vulnerable to CORS Misconfiguration
CVE-2023-37526 
6.5MEDIUM
What is CVE-2023-37526?
A significant security concern has been identified in the HCL DRYiCE Lucy mobile application due to a misconfiguration of Cross Origin Resource Sharing (CORS). This vulnerability permits unauthorized access to application resources from untrusted web domains. As a result, attackers could exploit this flaw to perform cache poisoning attacks, potentially compromising the integrity and confidentiality of user data. Proper configuration and validation of CORS policies are essential to mitigate this risk and ensure secure application functionality.
Affected Version(s)
DRYiCE Lucy v9