Vulnerability in HCL Domino Volt Allows Unsafe File Uploads and JavaScript Execution
CVE-2022-42449

4.6MEDIUM

Key Information:

Vendor
CVE Published:
30 April 2025

What is CVE-2022-42449?

HCL Domino Volt exhibits a vulnerability that permits the upload of .html files due to an unsafe default file type filter policy. This flaw can lead to the execution of arbitrary and potentially harmful JavaScript in applications deployed on the platform. By exploiting this vulnerability, attackers may manipulate user sessions or execute malicious scripts, thereby compromising application security and user data integrity. It is essential for developers and organizations utilizing HCL Domino Volt to review their file handling policies and implement necessary security measures to mitigate these risks.

Affected Version(s)

HCL Domino Volt 1.0 - 1.0.5

References

CVSS V3.1

Score:
4.6
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.