Stored Cross-Site Scripting Vulnerability in HCL Notes
CVE-2020-14240

6.1MEDIUM

Key Information:

Status
Vendor
CVE Published:
5 November 2020

What is CVE-2020-14240?

HCL Notes versions prior to 9.0.1 FP10 IF8, 10.0.1 FP6, and 11.0.1 FP1 are vulnerable to a stored cross-site scripting issue, allowing an attacker to embed malicious scripts. These scripts may be executed in the context of a user's browser, potentially compromising user sessions by stealing cookie-based authentication credentials and exposing sensitive information.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

Affected Version(s)

HCL Notes HCL Notes versions previous to releases 9.0.1 FP10 IF8, 10.0.1 FP6 and 11.0.1 FP1

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.