Lucene search

K
cvelistHCLCVELIST:CVE-2020-14225
HistoryDec 21, 2020 - 5:09 p.m.

CVE-2020-14225

2020-12-2117:09:24
HCL
www.cve.org
3
hcl inotes
tabnabbing
vulnerability
improper sanitization
message content
remote attacker
unauthenticated
sensitive information
phishing attack

EPSS

0.002

Percentile

59.8%

HCL iNotes is susceptible to a Tabnabbing vulnerability caused by improper sanitization of message content. A remote unauthenticated attacker could use this vulnerability to trick the end user into entering sensitive information such as credentials, e.g. as part of a phishing attack.

CNA Affected

[
  {
    "product": "HCL iNotes",
    "vendor": "n/a",
    "versions": [
      {
        "status": "affected",
        "version": "versions previous to releases 9.0.1 FP10 IF6"
      },
      {
        "status": "affected",
        "version": "10.0.1 FP5 and 11.0.1"
      }
    ]
  }
]

EPSS

0.002

Percentile

59.8%

Related for CVELIST:CVE-2020-14225