CVE-2024-42180

low

Description

HCL MyXalytics is affected by a malicious file upload vulnerability. The application accepts invalid file uploads, including incorrect content types, double extensions, null bytes, and special characters, allowing attackers to upload and execute malicious files.

References

https://support.hcl-software.com/csm?id=kb_article&sysparm_article=KB0118149

Details

Source: Mitre, NVD

Published: 2025-01-12

Updated: 2025-01-12

Risk Information

CVSS v2

Base Score: 0.8

Vector: CVSS2#AV:L/AC:H/Au:M/C:N/I:P/A:N

Severity: Low

CVSS v3

Base Score: 1.6

Vector: CVSS:3.0/AV:P/AC:H/PR:H/UI:R/S:U/C:N/I:L/A:N

Severity: Low