CVE-2020-14271: XSS
HCL iNotes v9, v10 and v11 is susceptible to a Stored Cross-Site Scripting (XSS) vulnerability due to improper handling of message content. An unauthenticated remote attacker could exploit this vulnerability using specially-crafted markup to execute script in a victim's web browser within the security context of the hosting Web site and/or steal the victim's cookie-based authentication credentials.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this HCL iNotes vulnerability?
The vulnerability ID for this HCL iNotes vulnerability is CVE-2020-14271.
What is the severity of CVE-2020-14271?
The severity of CVE-2020-14271 is medium (6.1).
How does the HCL iNotes vulnerability CVE-2020-14271 work?
The HCL iNotes vulnerability CVE-2020-14271 is a Stored Cross-Site Scripting (XSS) vulnerability that allows an unauthenticated remote attacker to execute script in a victim's web browser.
Which versions of HCL iNotes are affected by CVE-2020-14271?
HCL iNotes versions 9, 10, and 11 are affected by CVE-2020-14271.
How do I fix the HCL iNotes vulnerability CVE-2020-14271?
To fix the HCL iNotes vulnerability CVE-2020-14271, you should update to a version that includes the security patch provided by HCL.