Insecure Cookie Handling in HCL AION Leads to Cross-Site Request Risks
CVE-2025-52628
4.6MEDIUM
What is CVE-2025-52628?
HCL AION version 2.0 is affected by a vulnerability that involves the improper handling of cookie attributes, specifically the SameSite attribute. This flaw allows cookies to be transmitted during cross-site requests, which can heighten the risk of cross-site request forgery (CSRF) attacks and similar security threats. Addressing this vulnerability is crucial for maintaining the integrity and security of web applications and preventing unauthorized actions triggered by exploited cookies.
Affected Version(s)
AION 2.0