4.6

CVE-2022-44760

HCL Leap is affected by an unrestricted upload of file with dangerous type vulnerability

Unsafe default file type filter policy in HCL
Leap allows execution of unsafe JavaScript in deployed applications.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
HcltechHcl Leap Version >= 9.0 < 9.3.1
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.27% 0.498
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
psirt@hcl.com 4.6 2.1 2.5
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:N
CWE-434 Unrestricted Upload of File with Dangerous Type

The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.