CVE-2020-14240
05.11.2020, 17:15
HCL Notes versions previous to releases 9.0.1 FP10 IF8, 10.0.1 FP6 and 11.0.1 FP1 is susceptible to a Stored Cross-site Scripting (XSS) vulnerability. An attacker could use this vulnerability to execute script in a victim's Web browser within the security context of the hosting Web site and/or steal the victim's cookie-based authentication credentials.
Vendor | Product | Version |
---|---|---|
hcltech | notes | 9.0 ≤ 𝑥 ≤ 9.0.1 |
hcltech | notes | 10.0 ≤ 𝑥 ≤ 10.0.1 |
hcltech | notes | 11.0 ≤ 𝑥 ≤ 11.0.1 |
hcltech | notes | 9.0.1:fp10 |
hcltech | notes | 9.0.1:fp10if1 |
hcltech | notes | 9.0.1:fp10if2 |
hcltech | notes | 9.0.1:fp10if3 |
hcltech | notes | 9.0.1:fp10if4 |
hcltech | notes | 9.0.1:fp10if5 |
hcltech | notes | 9.0.1:fp10if6 |
hcltech | notes | 9.0.1:fp10if7 |
hcltech | notes | 9.0.1:fp1if1 |
hcltech | notes | 9.0.1:fp1if2 |
hcltech | notes | 9.0.1:fp2if1 |
hcltech | notes | 9.0.1:fp2if2 |
hcltech | notes | 9.0.1:fp2if3 |
hcltech | notes | 9.0.1:fp2if4 |
hcltech | notes | 9.0.1:fp3if1 |
hcltech | notes | 9.0.1:fp3if2 |
hcltech | notes | 9.0.1:fp3if3 |
hcltech | notes | 9.0.1:fp3if4 |
hcltech | notes | 9.0.1:fp4if1 |
hcltech | notes | 9.0.1:fp4if2 |
hcltech | notes | 9.0.1:fp5if1 |
hcltech | notes | 9.0.1:fp5if2 |
hcltech | notes | 9.0.1:fp5if3 |
hcltech | notes | 9.0.1:fp7if1 |
hcltech | notes | 9.0.1:fp7if2 |
hcltech | notes | 9.0.1:fp8if1 |
hcltech | notes | 9.0.1:fp9if1 |
hcltech | notes | 9.0.1:fp9if2 |
hcltech | notes | 10.0.1:fp1 |
hcltech | notes | 10.0.1:fp2 |
hcltech | notes | 10.0.1:fp3 |
hcltech | notes | 10.0.1:fp4 |
hcltech | notes | 10.0.1:fp5 |
𝑥
= Vulnerable software versions