ZeroHour

CVE-2024-42180

CVSS 3.1
9.8 critical
EPSS
<1%p17
Published
()
Modified
Description

HCL MyXalytics is affected by a malicious file upload vulnerability. The application accepts invalid file uploads, including incorrect content types, double extensions, null bytes, and special characters, allowing attackers to upload and execute malicious files.

Vendors
hcltech
Products
dryice myxalytics
Weakness
CWE-434
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.