Client-Side Script Injection in HCL Leap by HCL Technologies
CVE-2024-30147
6.5MEDIUM
What is CVE-2024-30147?
A vulnerability in HCL Leap allows attackers to inject malicious scripts into the authoring environment and deployed applications, posing significant risks to user data integrity and application security. This client-side script injection can be exploited through multiple vectors, making it essential for users to apply the latest updates to mitigate risks.
Affected Version(s)
HCL Leap < 9.3.8