Security Advisory

CVE-2020-4084

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2020-03-09 16:42:54
Last updated 2024-08-04 07:52:20
Assigner HCL
State PUBLISHED

Description

HCL Connections v5.5, v6.0, and v6.5 are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.