CVE-2020-14240: XSS
HCL Notes versions previous to releases 9.0.1 FP10 IF8, 10.0.1 FP6 and 11.0.1 FP1 is susceptible to a Stored Cross-site Scripting (XSS) vulnerability. An attacker could use this vulnerability to execute script in a victim's Web browser within the security context of the hosting Web site and/or steal the victim's cookie-based authentication credentials.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2020-14240?
The severity of CVE-2020-14240 is medium with a CVSS score of 6.1.
Which versions of HCL Notes are affected by CVE-2020-14240?
Versions previous to releases 9.0.1 FP10 IF8, 10.0.1 FP6, and 11.0.1 FP1 of HCL Notes are affected by CVE-2020-14240.
What is the vulnerability in HCL Notes?
CVE-2020-14240 is a Stored Cross-site Scripting (XSS) vulnerability in HCL Notes.
How can an attacker exploit CVE-2020-14240?
An attacker can use the CVE-2020-14240 vulnerability to execute script in a victim's web browser within the security context of the hosting website and potentially steal sensitive information.
Where can I find more information about CVE-2020-14240?
You can find more information about CVE-2020-14240 at the following link: https://support.hcltechsw.com/csm?id=kb_article&sysparm_article=KB0084789