← Back

CVE-2020-14271

nvd nist
Published: Dec 18, 2020Modified: Jun 17, 2026

JSON object

Loading...
6.1
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Exploitability: 2.8 / Impact: 2.7
Source: NVD

Description

HCL iNotes v9, v10 and v11 is susceptible to a Stored Cross-Site Scripting (XSS) vulnerability due to improper handling of message content. An unauthenticated remote attacker could exploit this vulnerability using specially-crafted markup to execute script in a victim's web browser within the security context of the hosting Web site and/or steal the victim's cookie-based authentication credentials.

Affected (10)

Products: Hcltech: Hcl Inotes
1 product
Hcl Inotes
Configuration A
10 vulnerable
Vulnerable SoftwareAffected Versions
Hcltech
From 11.0.0 to 11.0.1
From 9.0 to 10.0.1
Version 10.0.1
Version 10.0.1 fixpack1
Version 10.0.1 fixpack2
Version 10.0.1 fixpack3
Version 10.0.1 fixpack4
Version 10.0.1 fixpack5
Version 11.0.1
Version 11.0.1 fixpack1

References (2)

Timeline

No history available yet.