Impact
Improper neutralization of user input during web page generation in HCL Notes leads to a reflected cross‑site scripting flaw that allows an attacker to inject and execute arbitrary JavaScript code in the context of a victim browser session. Successful exploitation results in the execution of malicious scripts as if they were part of the legitimate web interface, potentially providing the attacker with full control over the victim’s session and access to sensitive data exposed through the Notes application.
Affected Systems
The vulnerability affects HCL Software’s HCL Notes application, specifically Release 12.0.2FP5HF8 running on Linux 4.18.0‑553.52.1.El8_10.X64_64#1. Users of this exact release on the specified Linux kernel are at risk.
Risk and Exploitability
The CVSS score of 5.5 indicates moderate severity, while the EPSS score of less than 1% shows a low likelihood of widespread exploitation. The vulnerability is not listed in the CISA KEV catalog. Based on the description, it is inferred that attackers could craft a malicious URL containing the reflected payload and entice a target to click it, thereby triggering script execution in the victim’s browser. No elevated privileges are required to perform the attack, but user interaction is typically necessary.
OpenCVE Enrichment