Low
CVSS: 3.2
Missing "no cache" headers in HCL Leap permits sensitive data to be cached.
Low
CVSS: 3.2
Missing "no cache" headers in HCL Leap permits user directory information to be cached.
Medium
CVSS: 4.6
Unsafe default file type filter policy in HCL
Leap allows execution of unsafe JavaScript in deployed applications.
Medium
CVSS: 4.6
Improper sanitization of SVG files in HCL Leap
allows client-side script injection in deployed applications.
Medium
CVSS: 6.5
Multiple vectors in HCL Leap allow client-side
script injection in the authoring environment and deployed applications.
Low
CVSS: 3.7
Insufficient sanitization in HCL Leap allows
client-side script injection in the authoring environment.
Medium
CVSS: 6.3
Insufficient sanitization policy in HCL Leap
allows client-side script injection in the deployed application through the
HTML widget.
Medium
CVSS: 5.3
Insufficient default configuration in HCL Leap
allows anonymous access to directory information.
High
CVSS: 7.1
Insufficient URI protocol whitelist in HCL Leap
allows script injection through query parameters.
Medium
CVSS: 4.1
Improper access control of endpoint in HCL Leap
allows certain admin users to import applications from the
server's filesystem.