PT-2020-13941 · Hcl · Hcl Digital Experience
Jason Wicker
·
Published
2020-11-05
·
Updated
2020-11-13
·
CVE-2020-14222
CVSS v3.1
6.1
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
HCL Digital Experience versions 8.5 through 9.5
Description
The issue concerns cross site scripting (XSS), specifically reflected XSS, where an attacker must induce a victim to click on a crafted URL from some delivery mechanism, such as email or another web site.
Recommendations
For HCL Digital Experience versions 8.5 through 9.5, consider implementing input validation and output encoding to prevent XSS attacks. As a temporary workaround, restrict access to potentially vulnerable subcomponents until a patch is available. Avoid using crafted URLs that could induce victims to click on them, and educate users about the risks of clicking on links from untrusted sources. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Hcl Digital Experience