Vulnerability Database

296,172

Total vulnerabilities in the database

CVE-2020-14225

HCL iNotes is susceptible to a Tabnabbing vulnerability caused by improper sanitization of message content. A remote unauthenticated attacker could use this vulnerability to trick the end user into entering sensitive information such as credentials, e.g. as part of a phishing attack.

  • Published: Dec 21, 2020
  • Updated: Apr 13, 2023
  • CVE: CVE-2020-14225
  • Severity: Medium
  • Exploit:

CVSS v3:

  • Severity: Medium
  • Score: 6.5
  • AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N

CVSS v2:

  • Severity: Low
  • Score: 4.3
  • AV:N/AC:M/Au:N/C:P/I:N/A:N

No CWE or OWASP classifications available.

Software From Fixed in
hcltechsw / hcl_inotes 9.0.1-fixpack_9 9.0.1-fixpack_9.x
hcltech / hcl_inotes 10.0.1-fixpack1 10.0.1-fixpack1.x
hcltech / hcl_inotes 10.0.1-fixpack2 10.0.1-fixpack2.x
hcltech / hcl_inotes 10.0.1-fixpack3 10.0.1-fixpack3.x
hcltech / hcl_inotes 10.0.1-fixpack4 10.0.1-fixpack4.x
hcltech / hcl_inotes 10.0.1 10.0.1.x
hcltechsw / hcl_inotes 9.0.1-fixpack_8 9.0.1-fixpack_8.x
hcltechsw / hcl_inotes 9.0.1-fixpack_9_interim_fix_1 9.0.1-fixpack_9_interim_fix_1.x
hcltechsw / hcl_inotes - 9.0.1
hcltech / hcl_inotes 11.0.0 11.0.0.x