First published: Wed Apr 30 2025(Updated: )
Unsafe default file type filter policy in HCL Domino Volt allows upload of .html file and execution of unsafe JavaScript in deployed applications
Credit: psirt@hcl.com
Affected Software | Affected Version | How to fix |
---|---|---|
HCL Domino Volt |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-42449 is classified as a high severity vulnerability due to the potential for executing unsafe JavaScript code.
To fix CVE-2022-42449, ensure to implement a secure file type filter that restricts the upload of .html files in HCL Domino Volt.
The impact of CVE-2022-42449 includes unauthorized execution of JavaScript that can lead to security breaches within deployed applications.
CVE-2022-42449 affects all versions of HCL Domino Volt that allow file uploads without proper filtering.
Yes, CVE-2022-42449 can be exploited remotely by attackers who upload malicious .html files to vulnerable applications.