← Back

CVE-2020-14225

nvd nist
Published: Dec 21, 2020Modified: Nov 21, 2024

JSON object

Loading...
6.5
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
Exploitability: 2.8 / Impact: 3.6
Source: NVD

Description

HCL iNotes is susceptible to a Tabnabbing vulnerability caused by improper sanitization of message content. A remote unauthenticated attacker could use this vulnerability to trick the end user into entering sensitive information such as credentials, e.g. as part of a phishing attack.

Affected (10)

1 product
Hcl Inotes
1 product
Hcl Inotes
Configuration A
10 vulnerable
Vulnerable SoftwareAffected Versions
Hcltech
Version 10.0.1
Version 10.0.1 fixpack1
Version 10.0.1 fixpack2
Version 10.0.1 fixpack3
Version 10.0.1 fixpack4
Version 11.0.0
Hcltechsw
Before 9.0.1
Version 9.0.1 fixpack_8
Version 9.0.1 fixpack_9
Version 9.0.1 fixpack_9_interim_fix_1

References (2)

Timeline

No history available yet.