CVE-2024-30155

Publication date

2025-03-26 07:59:52

Family

HCL

State

PUBLISHED

Description

HCL SX does not set the secure attribute on authorization tokens or session cookies. Attackers may potentially be able to obtain access to the cookie values via a Cross-Site-Forgery-Request (CSRF).