HCL Domino Volt and Domino Leap Improper SVG File Sanitization Vulnerability Allowing Client-Side Script Injection
Vulnerability
A vulnerability exists in HCL Domino Volt versions 1.0 prior to 1.0.5 and HCL Domino Leap versions 1.1 prior to 1.1.4, due to improper sanitization of SVG files. This flaw allows client-side script injection in applications deployed through these platforms.
Impact
Exploitation of this vulnerability enables client-side script injection, which could be used to execute malicious scripts in the context of the user.
Remediation
Users can upgrade to HCL Domino Leap 1.1.4, which addresses this vulnerability. Instructions for downloading the latest version of HCL Domino Leap are available on the HCL Software website.
Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM
Vulnerability Rating
Custom Algorithm
spread
0.0impact
1.7exploitability
6.4remediation
7.7relevance
0.0threat
0.0urgency
2.9incentive
1.7Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
