First published: Thu Jun 06 2024(Updated: )
The Domino Catalog template is susceptible to a Stored Cross-Site Scripting (XSS) vulnerability. An attacker with the ability to edit documents in the catalog application/database created from this template can embed a cross site scripting attack. The attack would be activated by an end user clicking it.
Credit: psirt@hcl.com
Affected Software | Affected Version | How to fix |
---|---|---|
HCL Domino | =11.0 | |
HCL Domino | =12.0 | |
HCL Domino | =14.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-37539 is classified as a medium severity vulnerability due to its potential for enabling stored cross-site scripting attacks.
To fix CVE-2023-37539, ensure that you apply the latest patches and updates provided by HCL Technologies for the affected Domino versions.
CVE-2023-37539 affects Domino versions 11.0, 12.0, and 14.0.
CVE-2023-37539 is a Stored Cross-Site Scripting (XSS) vulnerability.
An attacker with the ability to edit documents in the catalog application or database is capable of exploiting CVE-2023-37539.