First published: Fri Dec 18 2020(Updated: )
HCL iNotes v9, v10 and v11 is susceptible to a Stored Cross-Site Scripting (XSS) vulnerability due to improper handling of message content. An unauthenticated remote attacker could exploit this vulnerability using specially-crafted markup to execute script in a victim's web browser within the security context of the hosting Web site and/or steal the victim's cookie-based authentication credentials.
Credit: psirt@hcl.com
Affected Software | Affected Version | How to fix |
---|---|---|
Hcltech Hcl Inotes | >=9.0<10.0.1 | |
Hcltech Hcl Inotes | >=11.0.0<11.0.1 | |
Hcltech Hcl Inotes | =10.0.1 | |
Hcltech Hcl Inotes | =10.0.1-fixpack1 | |
Hcltech Hcl Inotes | =10.0.1-fixpack2 | |
Hcltech Hcl Inotes | =10.0.1-fixpack3 | |
Hcltech Hcl Inotes | =10.0.1-fixpack4 | |
Hcltech Hcl Inotes | =10.0.1-fixpack5 | |
Hcltech Hcl Inotes | =11.0.1 | |
Hcltech Hcl Inotes | =11.0.1-fixpack1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this HCL iNotes vulnerability is CVE-2020-14271.
The severity of CVE-2020-14271 is medium (6.1).
The HCL iNotes vulnerability CVE-2020-14271 is a Stored Cross-Site Scripting (XSS) vulnerability that allows an unauthenticated remote attacker to execute script in a victim's web browser.
HCL iNotes versions 9, 10, and 11 are affected by CVE-2020-14271.
To fix the HCL iNotes vulnerability CVE-2020-14271, you should update to a version that includes the security patch provided by HCL.