Insecure Cookie Handling in HCL AION Leads to Cross-Site Request Risks
CVE-2025-52628

4.6MEDIUM

Key Information:

Status
Vendor
CVE Published:
3 February 2026

What is CVE-2025-52628?

HCL AION version 2.0 is affected by a vulnerability that involves the improper handling of cookie attributes, specifically the SameSite attribute. This flaw allows cookies to be transmitted during cross-site requests, which can heighten the risk of cross-site request forgery (CSRF) attacks and similar security threats. Addressing this vulnerability is crucial for maintaining the integrity and security of web applications and preventing unauthorized actions triggered by exploited cookies.

Affected Version(s)

AION 2.0

References

CVSS V3.1

Score:
4.6
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.