CVE-2024-42180
LOW1.6CVSS v3
—CVSS v2
0.17%
EPSS (exploit probability)
CWE-434CWE
Description
HCL MyXalytics is affected by a malicious file upload vulnerability. The application accepts invalid file uploads, including incorrect content types, double extensions, null bytes, and special characters, allowing attackers to upload and execute malicious files.
CVSS v3 vector: CVSS:3.1/AV:P/AC:H/PR:H/UI:R/S:U/C:N/I:L/A:N
Affected routers (0)
No routers currently mapped to this CVE in our database.