HCL Domino Volt Unsafe Default File Type Filter Vulnerability Allowing JavaScript Execution

Vulnerability

A vulnerability exists in HCL Domino Volt versions 1.0 through 1.0.5 due to an unsafe default file type filter policy. This flaw allows the upload of .html and .htm files, enabling the execution of potentially harmful JavaScript in deployed applications.

Impact

Exploitation of this vulnerability could lead to the execution of unsafe JavaScript in applications deployed with HCL Domino Volt.

Remediation

Users can upgrade to HCL Domino Leap 1.1.1 to address this vulnerability. Instructions for downloading the latest version of HCL Domino Leap are available on the HCL Tech Software website.

Added: Sep 1, 2025, 7:22 PM
Updated: Sep 1, 2025, 7:22 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
0.6
exploitability
5.2
remediation
7.7
relevance
0.0
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.