First published: Thu Nov 05 2020(Updated: )
HCL Digital Experience 8.5, 9.0, 9.5 is susceptible to cross site scripting (XSS). One subcomponent is vulnerable to reflected XSS. In reflected XSS, an attacker must induce a victim to click on a crafted URL from some delivery mechanism (email, other web site).
Credit: psirt@hcl.com
Affected Software | Affected Version | How to fix |
---|---|---|
Hcltech Hcl Digital Experience | =8.5 | |
Hcltech Hcl Digital Experience | =9.0 | |
Hcltech Hcl Digital Experience | =9.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this vulnerability is CVE-2020-14222.
The severity level of CVE-2020-14222 is medium.
In HCL Digital Experience 8.5, 9.0, and 9.5, cross-site scripting (XSS) can occur when an attacker tricks a user into clicking on a crafted URL from an email or another website.
One subcomponent in HCL Digital Experience 8.5, 9.0, and 9.5 is vulnerable to reflected XSS.
To fix the cross-site scripting (XSS) vulnerability in HCL Digital Experience 8.5, 9.0, and 9.5, apply the patch or update provided by HCL Tech.