Client-side Script Injection Vulnerability in HCL Domino Volt
CVE-2022-42450
4.6MEDIUM
What is CVE-2022-42450?
An issue has been identified in HCL Domino Volt where improper sanitization of SVG files allows for client-side script injection. This vulnerability can be exploited when an attacker uploads a malicious SVG file, potentially leading to unauthorized access and control of deployed applications. Organizations using HCL Domino Volt must ensure proper validation and sanitization practices to mitigate the risks associated with this vulnerability.
Affected Version(s)
HCL Domino Volt 1.0 - 1.0.5
References
CVSS V3.1
Score:
4.6
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
