VYPR

Hcl Leap

by HCLTech

CVEs (11)

  • CVE-2022-38657HigFeb 12, 2023
    risk 0.53cvss 8.2epss 0.00

    An open redirect to malicious sites can occur when accessing the "Feedback" action on the manager page.

  • CVE-2023-37534HigApr 24, 2025
    risk 0.46cvss 7.1epss 0.00

    Insufficient URI protocol whitelist in HCL Leap allows script injection through query parameters.

  • CVE-2024-30147MedApr 24, 2025
    risk 0.42cvss 6.5epss 0.00

    Multiple vectors in HCL Leap allow client-side script injection in the authoring environment and deployed applications.

  • CVE-2024-30113MedApr 24, 2025
    risk 0.41cvss 6.3epss 0.00

    Insufficient sanitization policy in HCL Leap allows client-side script injection in the deployed application through the HTML widget.

  • CVE-2023-45720MedApr 24, 2025
    risk 0.34cvss 5.3epss 0.00

    Insufficient default configuration in HCL Leap allows anonymous access to directory information.

  • CVE-2022-44760MedApr 24, 2025
    risk 0.30cvss 4.6epss 0.00

    Unsafe default file type filter policy in HCL Leap allows execution of unsafe JavaScript in deployed applications.

  • CVE-2022-44759MedApr 24, 2025
    risk 0.30cvss 4.6epss 0.00

    Improper sanitization of SVG files in HCL Leap allows client-side script injection in deployed applications.

  • CVE-2024-30148MedApr 24, 2025
    risk 0.27cvss 4.1epss 0.00

    Improper access control of endpoint in HCL Leap allows certain admin users to import applications from the server's filesystem.

  • CVE-2024-30114LowApr 24, 2025
    risk 0.24cvss 3.7epss 0.00

    Insufficient sanitization in HCL Leap allows client-side script injection in the authoring environment.

  • CVE-2024-30127LowApr 24, 2025
    risk 0.21cvss 3.2epss 0.00

    Missing "no cache" headers in HCL Leap permits sensitive data to be cached.

  • CVE-2023-37516LowApr 24, 2025
    risk 0.21cvss 3.2epss 0.00

    Missing "no cache" headers in HCL Leap permits user directory information to be cached.