CVE-2025-62316Low· 2.3▾ SunlitHCL AION is affected by a vulnerability where certain security-related HTTP response headers are not properly configured. Absence of these headers may reduce the effectiveness of browser-based security controls and could expose the appli…
▾ Sunlit zone — Low / medium · no exploitation signal
impact 12.6 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
0.1%
HCL AION is affected by a vulnerability where certain security-related HTTP response headers are not properly configured. Absence of these headers may reduce the effectiveness of browser-based security controls and could expose the application to limited security risks under specific conditions.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2025-1018Medium· 5.3The fullscreen notification is prematurely hidden when fullscreen is re-requested quickly by the user
CVE-2025-1019Medium· 4.3The z-order of the browser windows could be manipulated to hide the fullscreen notification
CVE-2025-48597High· 7.8In multiple locations, there is a possible way to trick a user into accepting a permission due to a tapjacking/overlay attack
CVE-2025-6434Medium· 4.3The exception page for the HTTPS-Only feature, displayed when a website is opened via HTTP, lacked an anti-clickjacking delay, potentially allowing an attacker to trick a user into granting an exception and loading a webpage over HTTP
CVE-2025-5267Medium· 5.4A clickjacking vulnerability could have been used to trick a user into leaking saved payment card details to a malicious page
CVE-2025-1940High· 7.1A select option could partially obscure the confirmation prompt shown before launching external apps