PT-2025-18336 · Hcl · Hcl Leap

Published

2025-04-30

·

Updated

2025-11-04

·

CVE-2024-30115

CVSS v3.1

6.3

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:U/C:H/I:L/A:N
Name of the Vulnerable Software and Affected Versions HCL Leap (affected versions not specified)
Description An insufficient sanitization policy in HCL Leap allows client-side script injection in deployed applications through the HTML widget. This allows for the execution of malicious scripts within the context of a user's browser when interacting with the application. The issue involves a lack of proper input validation or encoding of data used in the HTML widget, enabling an attacker to inject arbitrary JavaScript code.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

XSS

Weakness Enumeration

Related Identifiers

CVE-2024-30115

Affected Products

Hcl Leap