CVE-2024-30155: Hcltech Hcl Sx
Medium severity, CVSS 4.3. EPSS: 0.2% chance of exploitation in the next 30 days.
HCL SX does not set the secure attribute on authorization tokens or session cookies. Attackers may potentially be able to obtain access to the cookie values via a Cross-Site-Forgery-Request (CSRF).
Affected products
- Hcltech Hcl Sx: version 21 only
Published 2025-03-26. Last modified 2026-06-17.