HCL AION Auto-Complete Vulnerability Allowing Sensitive Information Exposure
Vulnerability
A vulnerability exists in HCL AION v2.1.0, where the auto-complete feature is activated for certain input fields. This could lead to sensitive information being saved in the browser, with the potential for unintended disclosure under specific circumstances.
Impact
Enabling auto-complete for sensitive input fields could result in the unintentional exposure of confidential information stored in the browser.
Remediation
Users can upgrade to HCL AION v2.5.0, which addresses this vulnerability. The HCL AION support team can assist with the upgrade process.
Added: May 14, 2026, 5:48 PM
Updated: May 14, 2026, 5:48 PM
Vulnerability Rating
Custom Algorithm
spread
0.0impact
0.8exploitability
6.4remediation
0.0relevance
8.4threat
0.0urgency
2.9incentive
0.0Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
