CVE-2020-14222

MEDIUM

HCL Digital Experience 8.5, 9.0, 9.5 - Reflected Cross-Site Scripting

Title source: llm
STIX 2.1

Description

HCL Digital Experience 8.5, 9.0, 9.5 is susceptible to cross site scripting (XSS). One subcomponent is vulnerable to reflected XSS. In reflected XSS, an attacker must induce a victim to click on a crafted URL from some delivery mechanism (email, other web site).

References (1)

Core 1
Core References

Scores

CVSS v3 6.1
EPSS 0.0036
EPSS Percentile 58.2%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

Details

CWE
CWE-79
Status published
Products (3)
hcltech/hcl_digital_experience 8.5
hcltech/hcl_digital_experience 9.0
hcltech/hcl_digital_experience 9.5
Published Nov 05, 2020
Tracked Since Feb 18, 2026