CVE-2024-42180

Severity CVSS v4.0:
Pending analysis
Type:
CWE-434 Unrestricted Upload of File with Dangerous Type
Publication date:
12/01/2025
Last modified:
16/05/2025

Description

HCL MyXalytics is affected by a malicious file upload vulnerability. The application accepts invalid file uploads, including incorrect content types, double extensions, null bytes, and special characters, allowing attackers to upload and execute malicious files.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:hcltech:dryice_myxalytics:6.3:*:*:*:*:*:*:*