Vulnerability Description
HCL iNotes is susceptible to a Reflected Cross-site Scripting (XSS) vulnerability caused by improper validation of user-supplied input supplied with a form POST request. A remote attacker could exploit this vulnerability using a specially-crafted URL to execute script in a victim's web browser within the security context of the hosting web site and/or steal the victim's cookie-based authentication credentials.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Hcltech | Hcl Inotes | 9.0.1 |
| Hcltech | Domino | 9.0 |
Related Weaknesses (CWE)
References
- https://support.hcltechsw.com/csm?id=kb_article&sysparm_article=KB0100216Vendor Advisory
- https://support.hcltechsw.com/csm?id=kb_article&sysparm_article=KB0100216Vendor Advisory
FAQ
What is CVE-2022-27546?
CVE-2022-27546 is a vulnerability with a CVSS score of 8.3 (HIGH). HCL iNotes is susceptible to a Reflected Cross-site Scripting (XSS) vulnerability caused by improper validation of user-supplied input supplied with a form POST request. A remote attacker could exploi...
How severe is CVE-2022-27546?
CVE-2022-27546 has been rated HIGH with a CVSS base score of 8.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2022-27546?
Check the references section above for vendor advisories and patch information. Affected products include: Hcltech Hcl Inotes, Hcltech Domino.