CVE-2022-27562: HCL Domino Volt is affected by an unrestricted upload of a dangerous file type
Unsafe default file type filter policy in HCL Domino Volt allows upload of .html file and execution of unsafe JavaScript in deployed applications.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2022-27562?
CVE-2022-27562 has been assigned a medium severity rating due to the potential for unsafe JavaScript execution.
How do I fix CVE-2022-27562?
To fix CVE-2022-27562, you should implement a secure file type filter and restrict the upload of .html files in HCL Domino Volt.
What are the risks associated with CVE-2022-27562?
The main risk associated with CVE-2022-27562 is the possibility of executing unsafe JavaScript, leading to potential data breaches or application compromise.
What software versions are affected by CVE-2022-27562?
CVE-2022-27562 primarily affects HCL Domino Volt across all its versions.
Can CVE-2022-27562 affect deployed applications?
Yes, CVE-2022-27562 can affect deployed applications that allow the upload of .html files, leading to potential security vulnerabilities.