CVE-2022-44759

CVSS 3.1 Score 4.6 of 10 (medium)

Details

Published Apr 24, 2025
Updated: Apr 29, 2025
CWE ID 79

Summary

CVE-2022-44759 is a newly disclosed cybersecurity vulnerability affecting HCL Leap. This issue stems from improper sanitization of Scalable Vector Graphics (SVG) files in the platform. Maliciously crafted SVG files can inject client-side scripts into deployed applications, posing a significant risk to data confidentiality and integrity. Attackers can exploit this vulnerability by tricking users into opening or downloading a malicious SVG file, potentially leading to unauthorized access or data theft. Organizations using HCL Leap are advised to apply the available patch or upgrade to a secure version as soon as possible to mitigate this threat.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share