HCL Domino Volt and Domino Leap Insufficient URI Protocol Whitelist Script Injection Vulnerability

Vulnerability

A vulnerability allowing script injection through query parameters has been identified in HCL Domino Volt versions 1.0 prior to 1.0.5 and HCL Domino Leap versions 1.1 prior to 1.1.4. This issue arises from an inadequate URI protocol whitelist, which can be exploited to inject scripts via query parameters.

Impact

Exploitation of this vulnerability allows for script injection, which could be executed in the context of the user.

Remediation

Users can upgrade to HCL Domino Leap 1.1.3 to address this vulnerability. Instructions for downloading the latest version of HCL Domino Leap are available on the HCL Tech Software website.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
1.7
exploitability
6.4
remediation
7.7
relevance
0.0
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.