Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-3fq3-hrxw-v9q9

Опубликовано: 15 июл. 2026
Источник: github
Github: Не прошло ревью
CVSS4: 5.5

Описание

Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in HCL Notes from HCL Software allows reflected

Cross-Site Scripting (XSS).  Successful exploitation allows an attacker to execute arbitrary JavaScript in the context of another user.

This issue affects HCL Notes: Release 12.0.2FP5HF8 on Linux 4.18.0-553.52.1.El8_10.X64_64#1.

Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in HCL Notes from HCL Software allows reflected

Cross-Site Scripting (XSS).  Successful exploitation allows an attacker to execute arbitrary JavaScript in the context of another user.

This issue affects HCL Notes: Release 12.0.2FP5HF8 on Linux 4.18.0-553.52.1.El8_10.X64_64#1.

EPSS

Процентиль: 17%
0.00258
Низкий

5.5 Medium

CVSS4

Дефекты

CWE-79

Связанные уязвимости

nvd
17 дней назад

Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in HCL Notes from HCL Software allows reflected Cross-Site Scripting (XSS).  Successful exploitation allows an attacker to execute arbitrary JavaScript in the context of another user. This issue affects HCL Notes: Release 12.0.2FP5HF8 on Linux 4.18.0-553.52.1.El8_10.X64_64#1.

EPSS

Процентиль: 17%
0.00258
Низкий

5.5 Medium

CVSS4

Дефекты

CWE-79