CVE-2022-27546: HCL iNotes is susceptible to a Reflected Cross-site Scripting (XSS) vulnerability
HCL iNotes is susceptible to a Reflected Cross-site Scripting (XSS) vulnerability caused by improper validation of user-supplied input supplied with a form POST request. A remote attacker could exploit this vulnerability using a specially-crafted URL to execute script in a victim's web browser within the security context of the hosting web site and/or steal the victim's cookie-based authentication credentials.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2022-27546?
CVE-2022-27546 is classified as a medium severity vulnerability.
How do I fix CVE-2022-27546?
To fix CVE-2022-27546, users should update to the latest version of HCL iNotes or apply the relevant patches as provided by HCL.
What types of attacks can exploit CVE-2022-27546?
CVE-2022-27546 can be exploited through reflected Cross-site Scripting (XSS) attacks via specially-crafted URLs.
Which software versions are affected by CVE-2022-27546?
CVE-2022-27546 affects HCL iNotes versions 9.0.1 and all fixpacks, as well as major versions 10.0, 11.0, and 12.0.
Can CVE-2022-27546 affect users' data?
Yes, CVE-2022-27546 can potentially compromise user data by executing malicious scripts in the context of the user's session.