CVE-2024-23565: Hclsoftware Aftermarket Epc
Medium severity, CVSS 5.3. EPSS: 0.4% chance of exploitation in the next 30 days.
HCL Aftermarket EPC is vulnerable to email flooding as the application does not have a proper mail limitation mechanism at Forget Password functionality. The actor could b e a human or an automated process such as a virus or bot. This could be used to cause a denial of service, compromise program logic or other consequences.
Affected products
- Hclsoftware Aftermarket Epc: version 1.0.0 only
Published 2026-07-17. Last modified 2026-10-02.