CVE-2022-44759: HCL Leap is affected by Cross-site scripting (XSS)
Improper sanitization of SVG files in HCL Leap allows client-side script injection in deployed applications.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2022-44759?
CVE-2022-44759 has a medium severity rating due to the potential for client-side script injection.
How do I fix CVE-2022-44759?
To fix CVE-2022-44759, ensure proper sanitization of SVG files and update to the latest version of HCL Leap that addresses this vulnerability.
What is the impact of CVE-2022-44759 on applications?
The impact of CVE-2022-44759 includes the possibility of unauthorized script execution within deployed applications, leading to potential data leakage or user impersonation.
Is CVE-2022-44759 exploitable in all versions of HCL Leap?
CVE-2022-44759 affects specific versions of HCL Leap that do not implement proper SVG file sanitization, making them vulnerable to client-side attacks.
Who is affected by CVE-2022-44759?
Any user or organization using an affected version of HCL Leap that allows improperly sanitized SVG files is at risk from CVE-2022-44759.