CyberRota Analysis
AI-GeneratedHCL Notes on Linux is vulnerable to a reflected Cross-Site Scripting (XSS) flaw that allows attackers to execute arbitrary JavaScript in the context of another user. This could lead to unauthorized actions or data exposure, making it critical for organizations using HCL Notes, particularly those on the specified Linux version, to prioritize remediation efforts. Users should ensure they are running the latest version of HCL Notes to mitigate this risk.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in HCL Notes from HCL Software allows reflected Cross-Site Scripting (XSS). Successful exploitation allows an attacker to execute arbitrary JavaScript in the context of another user. This issue affects HCL Notes: Release 12.0.2FP5HF8 on Linux 4.18.0-553.52.1.El8_10.X64_64#1.