HCL Domino Volt and Domino Leap Client-Side Script Injection Vulnerability
Vulnerability
A client-side script injection vulnerability has been identified in HCL Domino Volt versions 1.0 prior to 1.0.5 and HCL Domino Leap versions 1.1 prior to 1.1.4. This vulnerability allows for the injection of scripts in both the authoring environment and deployed applications.
Impact
Exploitation of this vulnerability allows for client-side script injection, which could be used to execute malicious scripts in the context of the user.
Remediation
Users can upgrade to HCL Domino Leap 1.1.5 to address this vulnerability. Instructions for downloading the latest version of HCL Domino Leap are available on the HCL Tech Software website.
Vulnerability Rating
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
