Cross Site Scripting Vulnerability in HCL Digital Experience
CVE-2020-14222
6.1MEDIUM
Summary
HCL Digital Experience versions 8.5, 9.0, and 9.5 are susceptible to a cross site scripting (XSS) vulnerability, with a specific subcomponent facing the risk of reflected XSS. This type of vulnerability allows an attacker to craft a malicious URL, which they can deliver through various means, such as email or other websites. When a victim clicks on the deceptive link, it can execute arbitrary scripts in the context of their browser session, potentially compromising sensitive information. It is crucial for users of these versions to apply updates and follow security best practices to mitigate this risk.
Affected Version(s)
HCL Digital Experience 8.5, 9.0, 9.5
References
CVSS V3.1
Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved