HCL Domino Volt Unsafe Default File Type Filter Policy Vulnerability Allowing JavaScript Execution

Vulnerability

A vulnerability exists in HCL Domino Volt versions 1.0 to 1.0.5 due to an unsafe default file type filter policy. This flaw allows the upload of .html files, which can execute unsafe JavaScript in deployed applications.

Impact

Exploitation of this vulnerability could lead to the execution of malicious JavaScript in applications deployed with HCL Domino Volt.

Remediation

Users can upgrade to HCL Domino Leap 1.1.1 to address this vulnerability.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
0.6
exploitability
5.0
remediation
7.7
relevance
0.0
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.