HCL MyXalytics is affected by a malicious file upload vulnerability. The application accepts invalid file uploads, including incorrect content types, double extensions, null bytes, and special characters, allowing attackers to upload and execute malicious files.
Metrics
Affected Vendors & Products
References
History
Mon, 13 Jan 2025 16:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Sun, 12 Jan 2025 22:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | HCL MyXalytics is affected by a malicious file upload vulnerability. The application accepts invalid file uploads, including incorrect content types, double extensions, null bytes, and special characters, allowing attackers to upload and execute malicious files. | |
Title | HCL MyXalytics is affected by a malicious file upload vulnerability | |
Weaknesses | CWE-434 | |
References |
| |
Metrics |
cvssV3_1
|
MITRE
Status: PUBLISHED
Assigner: HCL
Published: 2025-01-12T21:53:03.369Z
Updated: 2025-01-13T15:14:02.864Z
Reserved: 2024-07-29T21:32:05.157Z
Link: CVE-2024-42180
Vulnrichment
Updated: 2025-01-13T15:13:51.166Z
NVD
Status : Received
Published: 2025-01-12T22:15:06.983
Modified: 2025-01-12T22:15:06.983
Link: CVE-2024-42180
Redhat
No data.