Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-5xjf-8xm7-6xx9

Опубликовано: 25 нояб. 2025
Источник: github
Github: Не прошло ревью
CVSS3: 8.1

Описание

HCL iNotes is susceptible to a Reflected Cross-site Scripting (XSS) vulnerability caused by improper validation of user-supplied input. A remote, unauthenticated attacker can specially craft a URL to execute script in a victim's Web browser within the security context of the hosting Web site and/or steal the victim's cookie-based authentication credentials.

HCL iNotes is susceptible to a Reflected Cross-site Scripting (XSS) vulnerability caused by improper validation of user-supplied input. A remote, unauthenticated attacker can specially craft a URL to execute script in a victim's Web browser within the security context of the hosting Web site and/or steal the victim's cookie-based authentication credentials.

EPSS

Процентиль: 13%
0.00044
Низкий

8.1 High

CVSS3

Дефекты

CWE-20

Связанные уязвимости

CVSS3: 8.1
nvd
3 месяца назад

HCL iNotes is susceptible to a Reflected Cross-site Scripting (XSS) vulnerability caused by improper validation of user-supplied input. A remote, unauthenticated attacker can specially craft a URL to execute script in a victim's Web browser within the security context of the hosting Web site and/or steal the victim's cookie-based authentication credentials.

EPSS

Процентиль: 13%
0.00044
Низкий

8.1 High

CVSS3

Дефекты

CWE-20