CVE-2025-55267: HCL Aftermarket DPC is affected by Unrestricted File Upload vulnerability
HCL Aftermarket DPC is affected by Unrestricted File Upload vulnerability, allows attacker to upload and execute malicious scripts, gaining full control over the server.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-55267?
CVE-2025-55267 is a high severity vulnerability due to its potential for allowing full control over the server through unrestricted file uploads.
How do I fix CVE-2025-55267?
To fix CVE-2025-55267, ensure that your HCL Aftermarket DPC installation restricts file uploads to allowed file types and implements proper validation and sanitization of user inputs.
What types of attacks could CVE-2025-55267 enable?
CVE-2025-55267 could enable remote code execution attacks, allowing attackers to upload malicious scripts that can compromise the server.
Which software is affected by CVE-2025-55267?
CVE-2025-55267 affects the HCL Aftermarket DPC software, which is susceptible to unrestricted file upload vulnerabilities.
How can I determine if my system is vulnerable to CVE-2025-55267?
You can determine vulnerability to CVE-2025-55267 by reviewing the file upload functionality in your HCL Aftermarket DPC installation for proper restrictions and validations.