Client-side Script Injection Vulnerability in HCL Leap
CVE-2024-30115
6.3MEDIUM
What is CVE-2024-30115?
A vulnerability exists in HCL Leap due to inadequate sanitization policies within the HTML widget. This flaw permits malicious actors to inject client-side scripts into deployed applications. The lack of proper input validation can lead to security breaches, allowing attackers to execute unauthorized actions in the context of user sessions, which may compromise sensitive data and application integrity.
Affected Version(s)
HCL Domino Leap 1.0 - 1.0.5; 1.1 - 1.1.3