CVE-2024-30114: HCL Leap is affected by a cross-site scripting (XSS) vulnerability
Published Apr 24, 2025
·Updated
Insufficient sanitization in HCL Leap allows client-side script injection in the authoring environment.
Affected Software
2 affected components
HCL Leap
hcltech Hcl Leap<9.3.6
Event History
Apr 24, 2025
CVE Published
via MITRE·04:22 PM
Data Sourced
via MITRE·04:22 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·05:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-30114?
CVE-2024-30114 is classified as a medium severity vulnerability due to the risk of client-side script injection.
2
How do I fix CVE-2024-30114?
To fix CVE-2024-30114, ensure proper sanitization of input in the authoring environment of HCL Leap.
3
What software versions are affected by CVE-2024-30114?
CVE-2024-30114 affects all versions of HCL Leap that do not implement adequate input sanitization.
4
What are the risks associated with CVE-2024-30114?
The risks associated with CVE-2024-30114 include potential client-side script injection that could lead to unauthorized actions or data exposure.
5
Is there a workaround for CVE-2024-30114?
Currently, there are no official workarounds for CVE-2024-30114, and upgrading to a patched version is recommended.