HCL MyXalytics is affected by a malicious file upload vulnerability. The application accepts invalid file uploads, including incorrect content types, double extensions, null bytes, and special characters, allowing attackers to upload and execute malicious files.
History

Mon, 13 Jan 2025 16:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sun, 12 Jan 2025 22:00:00 +0000

Type Values Removed Values Added
Description HCL MyXalytics is affected by a malicious file upload vulnerability. The application accepts invalid file uploads, including incorrect content types, double extensions, null bytes, and special characters, allowing attackers to upload and execute malicious files.
Title HCL MyXalytics is affected by a malicious file upload vulnerability
Weaknesses CWE-434
References
Metrics cvssV3_1

{'score': 1.6, 'vector': 'CVSS:3.1/AV:P/AC:H/PR:H/UI:R/S:U/C:N/I:L/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: HCL

Published: 2025-01-12T21:53:03.369Z

Updated: 2025-01-13T15:14:02.864Z

Reserved: 2024-07-29T21:32:05.157Z

Link: CVE-2024-42180

cve-icon Vulnrichment

Updated: 2025-01-13T15:13:51.166Z

cve-icon NVD

Status : Received

Published: 2025-01-12T22:15:06.983

Modified: 2025-01-12T22:15:06.983

Link: CVE-2024-42180

cve-icon Redhat

No data.