First published: Mon Dec 21 2020(Updated: )
HCL iNotes is susceptible to a Tabnabbing vulnerability caused by improper sanitization of message content. A remote unauthenticated attacker could use this vulnerability to trick the end user into entering sensitive information such as credentials, e.g. as part of a phishing attack.
Credit: psirt@hcl.com
Affected Software | Affected Version | How to fix |
---|---|---|
Hcltech Hcl Inotes | =10.0.1 | |
Hcltech Hcl Inotes | =10.0.1-fixpack1 | |
Hcltech Hcl Inotes | =10.0.1-fixpack2 | |
Hcltech Hcl Inotes | =10.0.1-fixpack3 | |
Hcltech Hcl Inotes | =10.0.1-fixpack4 | |
Hcltech Hcl Inotes | =11.0.0 | |
Hcltechsw Hcl Inotes | <9.0.1 | |
Hcltechsw Hcl Inotes | =9.0.1-fixpack_8 | |
Hcltechsw Hcl Inotes | =9.0.1-fixpack_9 | |
Hcltechsw Hcl Inotes | =9.0.1-fixpack_9_interim_fix_1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2020-14225.
The severity of CVE-2020-14225 is medium (6.5).
The Tabnabbing vulnerability in HCL iNotes is caused by improper sanitization of message content, allowing a remote unauthenticated attacker to trick end users into entering sensitive information through phishing attacks.
Yes, HCL iNotes version 10.0.1 is affected by this vulnerability.
To fix CVE-2020-14225 in HCL iNotes, you should update to a patched version such as 10.0.1-fixpack1, 10.0.1-fixpack2, 10.0.1-fixpack3, 10.0.1-fixpack4, or 11.0.0.