PT-2025-2627 · Hcl · Hcl Myxalytics
Published
2025-01-12
·
Updated
2025-05-16
·
CVE-2024-42180
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
The vulnerable software is HCL MyXalytics.
The vulnerability is a malicious file upload vulnerability, which allows attackers to upload and execute malicious files due to the application's acceptance of invalid file uploads, including incorrect content types, double extensions, null bytes, and special characters.
This vulnerability can be exploited by attackers to upload malicious files, potentially leading to code execution and other security issues.
The vulnerability has been identified in HCL MyXalytics, but the specific versions affected are not specified in the provided information.
It is crucial for users of HCL MyXalytics to ensure their software is up-to-date and to follow security best practices to mitigate the risk of this vulnerability being exploited.
#HCLMyXalytics #MaliciousFileUploadVulnerability #CVE202442180 #FileUploadVulnerability #SecurityVulnerability #HCLSoftware #MyXalyticsVulnerability #MaliciousFileUpload #VulnerabilityExploitation
Fix
Unrestricted File Upload
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Hcl Myxalytics