HCL MyXalytics is affected by a malicious file upload vulnerability. The application accepts invalid file uploads, including incorrect content types, double extensions, null bytes, and special characters, allowing attackers to upload and execute malicious files.
Metrics
Affected Vendors & Products
References
History
Fri, 16 May 2025 14:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Hcltech
Hcltech dryice Myxalytics |
|
CPEs | cpe:2.3:a:hcltech:dryice_myxalytics:6.3:*:*:*:*:*:*:* | |
Vendors & Products |
Hcltech
Hcltech dryice Myxalytics |
Mon, 13 Jan 2025 16:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Sun, 12 Jan 2025 22:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | HCL MyXalytics is affected by a malicious file upload vulnerability. The application accepts invalid file uploads, including incorrect content types, double extensions, null bytes, and special characters, allowing attackers to upload and execute malicious files. | |
Title | HCL MyXalytics is affected by a malicious file upload vulnerability | |
Weaknesses | CWE-434 | |
References |
| |
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: HCL
Published:
Updated: 2025-01-13T15:14:02.864Z
Reserved: 2024-07-29T21:32:05.157Z
Link: CVE-2024-42180

Updated: 2025-01-13T15:13:51.166Z

Status : Analyzed
Published: 2025-01-12T22:15:06.983
Modified: 2025-05-16T13:45:08.610
Link: CVE-2024-42180

No data.