Stored Cross-Site Scripting Vulnerability in HCL iNotes
CVE-2020-14271
6.1MEDIUM
What is CVE-2020-14271?
HCL iNotes versions 9, 10, and 11 are affected by a Stored Cross-Site Scripting vulnerability resulting from improper management of message content. An attacker, without the need for authentication, can exploit this issue by crafting malicious markup. This exploit allows the attacker to execute scripts in the context of a victim's web browser while accessing the site, posing a risk of stealing cookie-based authentication credentials and compromising user privacy.
Affected Version(s)
HCL iNotes v9, v10, v11