Cross-Site Scripting Vulnerability in HCL Digital Experience Products
CVE-2020-4081

6.1MEDIUM

Key Information:

Vendor
CVE Published:
2 February 2021

Summary

The HCL Digital Experience versions 8.5, 9.0, and 9.5 contain a cross-site scripting (XSS) vulnerability in the WSRP consumer component. This allows attackers to inject malicious scripts into web pages viewed by users, potentially compromising sensitive data. Users and organizations utilizing these versions should take immediate action to mitigate the risks associated with this vulnerability by following recommended security practices.

Affected Version(s)

HCL Digital Experience 8.5

HCL Digital Experience 9.0

HCL Digital Experience 9.5

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.