PT-2020-13941 · Hcl · Hcl Digital Experience

Jason Wicker

·

Published

2020-11-05

·

Updated

2020-11-13

·

CVE-2020-14222

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions HCL Digital Experience versions 8.5 through 9.5
Description The issue concerns cross site scripting (XSS), specifically reflected XSS, where an attacker must induce a victim to click on a crafted URL from some delivery mechanism, such as email or another web site.
Recommendations For HCL Digital Experience versions 8.5 through 9.5, consider implementing input validation and output encoding to prevent XSS attacks. As a temporary workaround, restrict access to potentially vulnerable subcomponents until a patch is available. Avoid using crafted URLs that could induce victims to click on them, and educate users about the risks of clicking on links from untrusted sources. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-14222

Affected Products

Hcl Digital Experience