VYPR
Medium severity4.6NVD Advisory· Published Apr 24, 2025· Updated Jun 17, 2026

CVE-2022-44759

CVE-2022-44759

Description

Improper sanitization of SVG files in HCL Leap allows client-side script injection in deployed applications.

Affected products

3
  • cpe:2.3:a:hcltech:hcl_leap:*:*:*:*:*:*:*:*
    Range: >=9.0,<9.3.1
  • HCL Software/Leapllm-create2 versions
    (expand)+ 1 more
    • (no CPE)
    • (no CPE)range: 9.0 - 9.3

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.