Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in HCL Notes from HCL Software allows reflected
Cross-Site Scripting (XSS).
Successful exploitation allows an attacker to execute arbitrary JavaScript in the context of another user.
This issue affects HCL Notes: Release 12.0.2FP5HF8 on Linux 4.18.0-553.52.1.El8_10.X64_64#1.
CVSS
No CVSS.
References
Configurations
No configuration.
History
15 Jul 2026, 16:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-07-15 16:16
Updated : 2026-07-15 21:00
NVD link : CVE-2026-9007
Mitre link : CVE-2026-9007
CVE.ORG link : CVE-2026-9007
JSON object : View
Products Affected
No product.
CWE
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
