Session Fixation Vulnerability in HCL MyXalytics Platform
CVE-2024-42170
6.8MEDIUM
Key Information:
- Vendor
- HCL Software Software
- Status
- Dryice Myxalytics
- Vendor
- CVE Published:
- 11 January 2025
Summary
HCL MyXalytics is susceptible to a session fixation vulnerability, allowing cyber criminals to exploit this flaw by sending specially crafted URLs that include a session token. If a victim unwittingly clicks such a link, an attacker can hijack the user's login session, potentially gaining unauthorized access to sensitive information. This poses a significant risk to user data security, necessitating prompt awareness and mitigation strategies.
Affected Version(s)
DRYiCE MyXalytics 6.3
References
CVSS V3.1
Score:
6.8
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved