Client-side Script Injection Vulnerability in HCL Leap
CVE-2024-30115

6.3MEDIUM

Key Information:

Vendor
CVE Published:
30 April 2025

What is CVE-2024-30115?

A vulnerability exists in HCL Leap due to inadequate sanitization policies within the HTML widget. This flaw permits malicious actors to inject client-side scripts into deployed applications. The lack of proper input validation can lead to security breaches, allowing attackers to execute unauthorized actions in the context of user sessions, which may compromise sensitive data and application integrity.

Affected Version(s)

HCL Domino Leap 1.0 - 1.0.5; 1.1 - 1.1.3

References

CVSS V3.1

Score:
6.3
Severity:
MEDIUM
Confidentiality:
High
Integrity:
Low
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

.