Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2020-14240

HCL Notes versions previous to releases 9.0.1 FP10 IF8, 10.0.1 FP6 and 11.0.1 FP1 is susceptible to a Stored Cross-site Scripting (XSS) vulnerability. An attacker could use this vulnerability to execute script in a victim's Web browser within the security context of the hosting Web site and/or steal the victim's cookie-based authentication credentials.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.003
EPSS Ranking 54.6%
CVSS Severity
CVSS v3 Score 6.1
CVSS v2 Score 4.3
Products affected by CVE-2020-14240
  • Hcltech » Notes » Version: 10.0
    cpe:2.3:a:hcltech:notes:10.0
  • Hcltech » Notes » Version: 10.0.0
    cpe:2.3:a:hcltech:notes:10.0.0
  • Hcltech » Notes » Version: 10.0.1
    cpe:2.3:a:hcltech:notes:10.0.1
  • Hcltech » Notes » Version: 11.0
    cpe:2.3:a:hcltech:notes:11.0
  • Hcltech » Notes » Version: 11.0.1
    cpe:2.3:a:hcltech:notes:11.0.1
  • Hcltech » Notes » Version: 9.0
    cpe:2.3:a:hcltech:notes:9.0
  • Hcltech » Notes » Version: 9.0.1
    cpe:2.3:a:hcltech:notes:9.0.1


Contact Us

Shodan ® - All rights reserved