HCL Domino Volt and Domino Leap Improper SVG File Sanitization Vulnerability Allowing Client-Side Script Injection

Vulnerability

A vulnerability exists in HCL Domino Volt versions 1.0 prior to 1.0.5 and HCL Domino Leap versions 1.1 prior to 1.1.4, due to improper sanitization of SVG files. This flaw allows client-side script injection in applications deployed through these platforms.

Impact

Exploitation of this vulnerability enables client-side script injection, which could be used to execute malicious scripts in the context of the user.

Remediation

Users can upgrade to HCL Domino Leap 1.1.4, which addresses this vulnerability. Instructions for downloading the latest version of HCL Domino Leap are available on the HCL Software website.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
1.7
exploitability
6.4
remediation
7.7
relevance
0.0
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.