Vulnerability Description
HCL iNotes is susceptible to a Tabnabbing vulnerability caused by improper sanitization of message content. A remote unauthenticated attacker could use this vulnerability to trick the end user into entering sensitive information such as credentials, e.g. as part of a phishing attack.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Hcltech | Hcl Inotes | 10.0.1 |
| Hcltechsw | Hcl Inotes | < 9.0.1 |
References
- https://support.hcltechsw.com/csm?id=kb_article&sysparm_article=KB0085915Vendor Advisory
- https://support.hcltechsw.com/csm?id=kb_article&sysparm_article=KB0085915Vendor Advisory
FAQ
What is CVE-2020-14225?
CVE-2020-14225 is a vulnerability with a CVSS score of 6.5 (MEDIUM). HCL iNotes is susceptible to a Tabnabbing vulnerability caused by improper sanitization of message content. A remote unauthenticated attacker could use this vulnerability to trick the end user into en...
How severe is CVE-2020-14225?
CVE-2020-14225 has been rated MEDIUM with a CVSS base score of 6.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2020-14225?
Check the references section above for vendor advisories and patch information. Affected products include: Hcltech Hcl Inotes, Hcltechsw Hcl Inotes.