CVE-2022-44759
CVSS 3.1 Score 4.6 of 10 (medium)
Details
Summary
CVE-2022-44759 is a newly disclosed cybersecurity vulnerability affecting HCL Leap. This issue stems from improper sanitization of Scalable Vector Graphics (SVG) files in the platform. Maliciously crafted SVG files can inject client-side scripts into deployed applications, posing a significant risk to data confidentiality and integrity. Attackers can exploit this vulnerability by tricking users into opening or downloading a malicious SVG file, potentially leading to unauthorized access or data theft. Organizations using HCL Leap are advised to apply the available patch or upgrade to a secure version as soon as possible to mitigate this threat.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.