CVE-2024-30113: HCL Leap is affected by a cross-site scripting (XSS) vulnerability
Published Apr 24, 2025
·Updated
Insufficient sanitization policy in HCL Leap allows client-side script injection in the deployed application through the HTML widget.
Affected Software
2 affected components
HCL Leap
hcltech Hcl Leap<9.3.6
Event History
Apr 24, 2025
CVE Published
via MITRE·04:23 PM
Data Sourced
via MITRE·04:23 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·05:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-30113?
CVE-2024-30113 is classified as a medium severity vulnerability due to the potential for client-side script injection.
2
How do I fix CVE-2024-30113?
To fix CVE-2024-30113, ensure proper sanitization of user input in the HTML widget within HCL Leap.
3
What software is affected by CVE-2024-30113?
CVE-2024-30113 affects HCL Leap across its various versions.
4
What are the risks associated with CVE-2024-30113?
The risks of CVE-2024-30113 include the potential for malicious script execution, which can lead to data theft or application compromise.
5
Is CVE-2024-30113 exploited in the wild?
As of now, there are no reported active exploits for CVE-2024-30113.