CVE-2024-30115: HCL Domino Volt and Domino Leap are affected by a cross-site scripting (XSS) vulnerability
Published Apr 30, 2025
·Updated
Insufficient sanitization policy in HCL Leap allows client-side script injection in the deployed application through the HTML widget.
Affected Software
3 affected components
HCL Domino Volt
HCL Domino Leap
hcltech Domino Leap>=1.1<1.1.4
Event History
Apr 30, 2025
CVE Published
via MITRE·09:14 PM
Data Sourced
via MITRE·09:14 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·10:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-30115?
CVE-2024-30115 is considered a moderate severity vulnerability due to its potential for client-side script injection.
2
How do I fix CVE-2024-30115?
To fix CVE-2024-30115, ensure that proper input sanitization is implemented within the HTML widget of HCL Domino Volt and HCL Domino Leap.
3
What type of vulnerabilities does CVE-2024-30115 involve?
CVE-2024-30115 involves insufficient sanitization policy vulnerabilities that allow client-side script injection.
4
Which software is affected by CVE-2024-30115?
CVE-2024-30115 affects HCL Domino Volt and HCL Domino Leap applications.
5
What are the risks associated with CVE-2024-30115?
The risks associated with CVE-2024-30115 include potential unauthorized access to user sessions and data manipulation via executed scripts.