VendorsHcltechhcl_inotes11.0.1
Vulnerabilities

Hcltech HCL Technologies HCL iNotes 11.0.1

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

5CVEs
CVE-2022-27546
HCL iNotes is susceptible to a Reflected Cross-site Scripting (XSS) vulnerability
Published 2022-08-29 · Modified
8.3EPSS 0.006
CVE-2022-27547
HCL iNotes is susceptible to a link to non-existent domain vulnerability.
Published 2022-08-29 · Modified
7.4EPSS 0.005
CVE-2020-14271
HCL iNotes v9, v10 and v11 is susceptible to a Stored Cross-Site Scripting (XSS) vulnerability due to improper handling of message content. An unauthenticated remote attacker could exploit this vulnerability using specially-crafted markup to execute script in a victim's web browser within the security context of the hosting Web site and/or steal the victim's cookie-based authentication credentials.
Published 2020-12-18 · Modified
6.1EPSS 0.011
CVE-2021-27760
HCL Notes 11.0 - 11.0.1 FP4 Sametime Embedded chat clients are vulnerable to group chats loading script on restart
Published 2022-05-06 · Modified
6.0EPSS 0.007
CVE-2020-4126
HCL iNotes is susceptible to a sensitive cookie exposure vulnerability. This can allow an unauthenticated remote attacker to capture the cookie by intercepting its transmission within an http session. Fixes are available in HCL Domino and iNotes versions 10.0.1 FP6 and 11.0.1 FP2 and later.
Published 2020-11-30 · Modified
5.9EPSS 0.007