CVE-2024-30145: HCL Domino Volt and Domino Leap are affected by a cross-site scripting (XSS) vulnerability
Published Apr 30, 2025
·Updated
Multiple vectors in HCL Domino Volt and Domino Leap allow client-side script injection in the authoring environment and deployed applications.
Affected Software
3 affected components
HCL Domino Volt
HCL Domino Leap
hcltech Domino Leap>=1.1<1.1.5
Event History
Apr 30, 2025
CVE Published
via MITRE·09:15 PM
Data Sourced
via MITRE·09:15 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·10:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-30145?
CVE-2024-30145 is considered a high-severity vulnerability due to the potential for client-side script injection.
2
How do I fix CVE-2024-30145?
To fix CVE-2024-30145, apply the latest patches provided by HCL for Domino Volt and Domino Leap.
3
What types of applications are affected by CVE-2024-30145?
CVE-2024-30145 affects applications developed in HCL Domino Volt and Domino Leap that are deployed in the authoring environment.
4
What kind of attacks can be executed through CVE-2024-30145?
CVE-2024-30145 can be exploited for client-side script injection attacks, potentially compromising application security.
5
Is there a workaround for CVE-2024-30145 until a patch is available?
Currently, the best practice is to limit the use of affected features in HCL Domino Volt and Domino Leap until a patch is applied.