CVE-2020-14271
Severity CVSS v4.0:
Pending analysis
Type:
CWE-79
Cross-Site Scripting (XSS)
Publication date:
18/12/2020
Last modified:
22/12/2020
Description
HCL iNotes v9, v10 and v11 is susceptible to a Stored Cross-Site Scripting (XSS) vulnerability due to improper handling of message content. An unauthenticated remote attacker could exploit this vulnerability using specially-crafted markup to execute script in a victim's web browser within the security context of the hosting Web site and/or steal the victim's cookie-based authentication credentials.
Impact
Base Score 3.x
6.10
Severity 3.x
MEDIUM
Base Score 2.0
4.30
Severity 2.0
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:hcltech:hcl_inotes:*:*:*:*:*:*:*:* | 9.0 (including) | 10.0.1 (excluding) |
| cpe:2.3:a:hcltech:hcl_inotes:*:*:*:*:*:*:*:* | 11.0.0 (including) | 11.0.1 (excluding) |
| cpe:2.3:a:hcltech:hcl_inotes:10.0.1:-:*:*:*:*:*:* | ||
| cpe:2.3:a:hcltech:hcl_inotes:10.0.1:fixpack1:*:*:*:*:*:* | ||
| cpe:2.3:a:hcltech:hcl_inotes:10.0.1:fixpack2:*:*:*:*:*:* | ||
| cpe:2.3:a:hcltech:hcl_inotes:10.0.1:fixpack3:*:*:*:*:*:* | ||
| cpe:2.3:a:hcltech:hcl_inotes:10.0.1:fixpack4:*:*:*:*:*:* | ||
| cpe:2.3:a:hcltech:hcl_inotes:10.0.1:fixpack5:*:*:*:*:*:* | ||
| cpe:2.3:a:hcltech:hcl_inotes:11.0.1:-:*:*:*:*:*:* | ||
| cpe:2.3:a:hcltech:hcl_inotes:11.0.1:fixpack1:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page



