PT-2025-2627 · Hcl · Hcl Myxalytics

Published

2025-01-12

·

Updated

2025-05-16

·

CVE-2024-42180

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The vulnerable software is HCL MyXalytics. The vulnerability is a malicious file upload vulnerability, which allows attackers to upload and execute malicious files due to the application's acceptance of invalid file uploads, including incorrect content types, double extensions, null bytes, and special characters. This vulnerability can be exploited by attackers to upload malicious files, potentially leading to code execution and other security issues. The vulnerability has been identified in HCL MyXalytics, but the specific versions affected are not specified in the provided information. It is crucial for users of HCL MyXalytics to ensure their software is up-to-date and to follow security best practices to mitigate the risk of this vulnerability being exploited. #HCLMyXalytics #MaliciousFileUploadVulnerability #CVE202442180 #FileUploadVulnerability #SecurityVulnerability #HCLSoftware #MyXalyticsVulnerability #MaliciousFileUpload #VulnerabilityExploitation

Fix

Unrestricted File Upload

Weakness Enumeration

Related Identifiers

CVE-2024-42180

Affected Products

Hcl Myxalytics