CVE-2022-42449: HCL Domino Volt is affected by an unrestricted upload of a dangerous file type
Unsafe default file type filter policy in HCL Domino Volt allows upload of .html file and execution of unsafe JavaScript in deployed applications
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2022-42449?
CVE-2022-42449 is classified as a high severity vulnerability due to the potential for executing unsafe JavaScript code.
How do I fix CVE-2022-42449?
To fix CVE-2022-42449, ensure to implement a secure file type filter that restricts the upload of .html files in HCL Domino Volt.
What is the impact of CVE-2022-42449?
The impact of CVE-2022-42449 includes unauthorized execution of JavaScript that can lead to security breaches within deployed applications.
Which versions of HCL Domino Volt are affected by CVE-2022-42449?
CVE-2022-42449 affects all versions of HCL Domino Volt that allow file uploads without proper filtering.
Can CVE-2022-42449 be exploited remotely?
Yes, CVE-2022-42449 can be exploited remotely by attackers who upload malicious .html files to vulnerable applications.