6.1

CVE-2020-14240

HCL Notes versions previous to releases 9.0.1 FP10 IF8, 10.0.1 FP6 and 11.0.1 FP1 is susceptible to a Stored Cross-site Scripting (XSS) vulnerability. An attacker could use this vulnerability to execute script in a victim's Web browser within the security context of the hosting Web site and/or steal the victim's cookie-based authentication credentials.

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
HcltechNotes Version >= 9.0 <= 9.0.1
HcltechNotes Version >= 10.0 <= 10.0.1
HcltechNotes Version >= 11.0 <= 11.0.1
HcltechNotes Version9.0.1 Updatefp10
HcltechNotes Version9.0.1 Updatefp10if1
HcltechNotes Version9.0.1 Updatefp10if2
HcltechNotes Version9.0.1 Updatefp10if3
HcltechNotes Version9.0.1 Updatefp10if4
HcltechNotes Version9.0.1 Updatefp10if5
HcltechNotes Version9.0.1 Updatefp10if6
HcltechNotes Version9.0.1 Updatefp10if7
HcltechNotes Version9.0.1 Updatefp1if1
HcltechNotes Version9.0.1 Updatefp1if2
HcltechNotes Version9.0.1 Updatefp2if1
HcltechNotes Version9.0.1 Updatefp2if2
HcltechNotes Version9.0.1 Updatefp2if3
HcltechNotes Version9.0.1 Updatefp2if4
HcltechNotes Version9.0.1 Updatefp3if1
HcltechNotes Version9.0.1 Updatefp3if2
HcltechNotes Version9.0.1 Updatefp3if3
HcltechNotes Version9.0.1 Updatefp3if4
HcltechNotes Version9.0.1 Updatefp4if1
HcltechNotes Version9.0.1 Updatefp4if2
HcltechNotes Version9.0.1 Updatefp5if1
HcltechNotes Version9.0.1 Updatefp5if2
HcltechNotes Version9.0.1 Updatefp5if3
HcltechNotes Version9.0.1 Updatefp7if1
HcltechNotes Version9.0.1 Updatefp7if2
HcltechNotes Version9.0.1 Updatefp8if1
HcltechNotes Version9.0.1 Updatefp9if1
HcltechNotes Version9.0.1 Updatefp9if2
HcltechNotes Version10.0.1 Updatefp1
HcltechNotes Version10.0.1 Updatefp2
HcltechNotes Version10.0.1 Updatefp3
HcltechNotes Version10.0.1 Updatefp4
HcltechNotes Version10.0.1 Updatefp5
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.32% 0.521
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 6.1 2.8 2.7
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
nvd@nist.gov 4.3 8.6 2.9
AV:N/AC:M/Au:N/C:N/I:P/A:N
CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.