First published: Wed Apr 30 2025(Updated: )
Unsafe default file type filter policy in HCL Domino Volt allows upload of .html file and execution of unsafe JavaScript in deployed applications.
Credit: psirt@hcl.com
Affected Software | Affected Version | How to fix |
---|---|---|
HCL Domino Volt |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-27562 has been assigned a medium severity rating due to the potential for unsafe JavaScript execution.
To fix CVE-2022-27562, you should implement a secure file type filter and restrict the upload of .html files in HCL Domino Volt.
The main risk associated with CVE-2022-27562 is the possibility of executing unsafe JavaScript, leading to potential data breaches or application compromise.
CVE-2022-27562 primarily affects HCL Domino Volt across all its versions.
Yes, CVE-2022-27562 can affect deployed applications that allow the upload of .html files, leading to potential security vulnerabilities.