CVEs (11)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
Missing "no cache" headers in HCL Leap permits sensitive data to be cached. |
Missing "no cache" headers in HCL Leap permits user directory information to be cached. |
Unsafe default file type filter policy in HCL
Leap allows execution of unsafe JavaScript in deployed applications. |
Improper sanitization of SVG files in HCL Leap
allows client-side script injection in deployed applications. |
Multiple vectors in HCL Leap allow client-side
script injection in the authoring environment and deployed applications. |
Insufficient sanitization in HCL Leap allows
client-side script injection in the authoring environment. |
Insufficient sanitization policy in HCL Leap
allows client-side script injection in the deployed application through the
HTML widget. |
Insufficient default configuration in HCL Leap
allows anonymous access to directory information. |
Insufficient URI protocol whitelist in HCL Leap
allows script injection through query parameters. |
Improper access control of endpoint in HCL Leap
allows certain admin users to import applications from the
server's filesystem. |
An open redirect to malicious sites can occur when accessing the "Feedback" action on the manager page.
|