Cross-Site Scripting Vulnerability in HCL Connections 5.5
CVE-2020-4082
5.4MEDIUM
What is CVE-2020-4082?
The help system of HCL Connections 5.5 is susceptible to cross-site scripting due to inadequate validation of user-supplied input. This vulnerability allows a remote attacker to craft a malicious URL, which, when clicked by a victim, can execute scripts in the user's web browser under the security context of the hosting site. This can lead to the theft of cookie-based authentication credentials, potentially compromising user accounts and sensitive data.
Affected Version(s)
"HCL Connections" "HCL Connections 5.5"