CVE-2025-52628: HCL AION is susceptible to Missing SameSite vulnerability
HCL AION is affected by a Cookie with Insecure, Improper, or Missing SameSite vulnerability. This can allow cookies to be sent in cross-site requests, potentially increasing exposure to cross-site request forgery and related security risks. This issue affects AION: 2.0.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-52628?
CVE-2025-52628 is considered a medium severity vulnerability due to the potential for cross-site request forgery risks.
How do I fix CVE-2025-52628?
To fix CVE-2025-52628, ensure that cookies are properly configured with the SameSite attribute to enhance security.
What impact does CVE-2025-52628 have on users?
CVE-2025-52628 can expose users to increased risk of cross-site request forgery attacks due to improper cookie handling.
What systems are affected by CVE-2025-52628?
CVE-2025-52628 affects HCL AION, particularly those instances with insecure cookie settings.
Is CVE-2025-52628 easy to exploit?
While the exploitation of CVE-2025-52628 may require specific conditions to be met, it can potentially be exploited in a variety of web applications vulnerable to cross-site request forgery.