Insufficient URI protocol whitelist in HCL Domino Volt and Domino Leap allow script injection through query parameters.
History

Wed, 30 Apr 2025 21:30:00 +0000

Type Values Removed Values Added
Description Insufficient URI protocol whitelist in HCL Domino Volt and Domino Leap allow script injection through query parameters.
Title HCL Domino Volt and Domino Leap are affected by a Cross-site scripting (XSS) vulnerability
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:H/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: HCL

Published: 2025-04-30T21:12:38.618Z

Updated: 2025-04-30T21:12:38.618Z

Reserved: 2023-07-06T16:29:45.713Z

Link: CVE-2023-37535

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2025-04-30T22:15:16.090

Modified: 2025-04-30T22:15:16.090

Link: CVE-2023-37535

cve-icon Redhat

No data.