Script Injection Vulnerability in HCL Leap Software
CVE-2023-37534
7.1HIGH
What is CVE-2023-37534?
An insufficient URI protocol whitelist in HCL Leap allows for script injection via compromised query parameters. This vulnerability can lead to potential exploitation, enabling attackers to execute malicious scripts, affecting the integrity and security of web applications that utilize HCL Leap. Organizations using this software must take proactive measures to assess their exposure and mitigate risks associated with this vulnerability.
Affected Version(s)
HCL Leap < 9.3.4