← Back

CVE-2022-27546

nvd nist
Published: Aug 29, 2022Modified: Jun 17, 2026

JSON object

Loading...
6.1
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Exploitability: 2.8 / Impact: 2.7
Source: NVD

Description

HCL iNotes is susceptible to a Reflected Cross-site Scripting (XSS) vulnerability caused by improper validation of user-supplied input supplied with a form POST request. A remote attacker could exploit this vulnerability using a specially-crafted URL to execute script in a victim's web browser within the security context of the hosting web site and/or steal the victim's cookie-based authentication credentials.

Affected (59)

2 products
Hcl Inotes
Domino
Configuration A
29 vulnerable
Vulnerable SoftwareAffected Versions
Hcltech
Version 10.0.1
Version 10.0.1 fixpack_1
Version 10.0.1 fixpack_2
Version 10.0.1 fixpack_3
Version 10.0.1 fixpack_4
Version 10.0.1 fixpack_5
Version 10.0.1 fixpack_6
Version 10.0.1 fixpack_7
Version 10.0.1 fixpack_8
Version 10.0
Version 11.0.1
Version 11.0.1 fixpack_1
Version 11.0.1 fixpack_2
Version 11.0.1 fixpack_3
Version 11.0.1 fixpack_4
Version 11.0.1 fixpack_5
Version 11.0
Version 12.0.1
Version 12.0.1 fixpack_1
Version 12.0
Version 9.0.1
Version 9.0.1 fixpack_10
Version 9.0.1 fixpack_3
Version 9.0.1 fixpack_4
Version 9.0.1 fixpack_5
Version 9.0.1 fixpack_6
Version 9.0.1 fixpack_7
Version 9.0.1 fixpack_8
Version 9.0.1 fixpack_9
Configuration B
30 vulnerable
Vulnerable SoftwareAffected Versions
Hcltech
Version 10.0.1
Version 10.0.1 fixpack_1
Version 10.0.1 fixpack_2
Version 10.0.1 fixpack_3
Version 10.0.1 fixpack_4
Version 10.0.1 fixpack_5
Version 10.0.1 fixpack_6
Version 10.0.1 fixpack_7
Version 10.0.1 fixpack_8
Version 10.0
Version 11.0.1
Version 11.0.1 fixpack_1
Version 11.0.1 fixpack_2
Version 11.0.1 fixpack_3
Version 11.0.1 fixpack_4
Version 11.0.1 fixpack_5
Version 11.0
Version 12.0.1
Version 12.0.1 fixpack_1
Version 12.0
Version 9.0.1
Version 9.0.1 fixpack_10
Version 9.0.1 fixpack_3
Version 9.0.1 fixpack_4
Version 9.0.1 fixpack_5
Version 9.0.1 fixpack_6
Version 9.0.1 fixpack_7
Version 9.0.1 fixpack_8
Version 9.0.1 fixpack_9
Version 9.0

References (2)

Timeline

No history available yet.