4.6
CVE-2022-44760
- EPSS 0.05%
- Veröffentlicht 24.04.2025 20:37:58
- Zuletzt bearbeitet 17.11.2025 21:48:08
- Quelle psirt@hcl.com
- CVE-Watchlists
- Unerledigt
Unsafe default file type filter policy in HCL Leap allows execution of unsafe JavaScript in deployed applications.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.05% | 0.148 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| psirt@hcl.com | 4.6 | 2.1 | 2.5 |
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:N
|
CWE-434 Unrestricted Upload of File with Dangerous Type
The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.