← Back

CVE-2020-14240

nvd nist
Published: Nov 5, 2020Modified: Jun 17, 2026

JSON object

Loading...
6.1
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Exploitability: 2.8 / Impact: 2.7
Source: NVD

Description

HCL Notes versions previous to releases 9.0.1 FP10 IF8, 10.0.1 FP6 and 11.0.1 FP1 is susceptible to a Stored Cross-site Scripting (XSS) vulnerability. An attacker could use this vulnerability to execute script in a victim's Web browser within the security context of the hosting Web site and/or steal the victim's cookie-based authentication credentials.

Affected (36)

Products: Hcltech: Notes
1 product
Notes
Configuration A
36 vulnerable
Vulnerable SoftwareAffected Versions
Hcltech
From 10.0 to 10.0.1
From 11.0 to 11.0.1
From 9.0 to 9.0.1
Version 10.0.1 fp1
Version 10.0.1 fp2
Version 10.0.1 fp3
Version 10.0.1 fp4
Version 10.0.1 fp5
Version 9.0.1 fp10
Version 9.0.1 fp10if1
Version 9.0.1 fp10if2
Version 9.0.1 fp10if3
Version 9.0.1 fp10if4
Version 9.0.1 fp10if5
Version 9.0.1 fp10if6
Version 9.0.1 fp10if7
Version 9.0.1 fp1if1
Version 9.0.1 fp1if2
Version 9.0.1 fp2if1
Version 9.0.1 fp2if2
Version 9.0.1 fp2if3
Version 9.0.1 fp2if4
Version 9.0.1 fp3if1
Version 9.0.1 fp3if2
Version 9.0.1 fp3if3
Version 9.0.1 fp3if4
Version 9.0.1 fp4if1
Version 9.0.1 fp4if2
Version 9.0.1 fp5if1
Version 9.0.1 fp5if2
Version 9.0.1 fp5if3
Version 9.0.1 fp7if1
Version 9.0.1 fp7if2
Version 9.0.1 fp8if1
Version 9.0.1 fp9if1
Version 9.0.1 fp9if2

References (2)

Timeline

No history available yet.