Executive brief
HCL Aftermarket EPC, a platform used for managing electronic parts catalogs, is vulnerable to clickjacking. This flaw allows an attacker to trick users into performing unintended actions by overlaying the application's interface on a malicious website. Successful exploitation could lead to unauthorized configuration changes, sensitive information disclosure, or phishing attacks against employees.
Technical details
A clickjacking (Cross-Frame Scripting) vulnerability exists in HCL Aftermarket EPC version 1.0.0 due to insufficient frame-busting protections or missing security headers like X-Frame-Options or Content-Security-Policy (frame-ancestors). An unauthenticated remote attacker can embed the vulnerable application into an iFrame on a controlled malicious website. By enticing a legitimate user to visit the site and interact with the hidden frame, the attacker can facilitate UI redressing attacks, potentially leading to Cross-Site Request Forgery (CSRF) or the leakage of sensitive session information. The vulnerability is tracked as CVE-2024-23570.
Affected products
- HCL Software Aftermarket EPC 1.0.0
Timeline
- 2026-07-17: disclosed: Initial publication of the CVE record and HCL security bulletin.
- 2026-07-17: advisory