HCL Domino Volt and Domino Leap Insufficient URI Protocol Whitelist Script Injection Vulnerability
Vulnerability
A vulnerability allowing script injection through query parameters has been identified in HCL Domino Volt versions 1.0 prior to 1.0.5 and HCL Domino Leap versions 1.1 prior to 1.1.4. This issue arises from an inadequate URI protocol whitelist, which can be exploited to inject scripts via query parameters.
Impact
Exploitation of this vulnerability allows for script injection, which could be executed in the context of the user.
Remediation
Users can upgrade to HCL Domino Leap 1.1.3 to address this vulnerability. Instructions for downloading the latest version of HCL Domino Leap are available on the HCL Tech Software website.
Vulnerability Rating
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
