#VU45779 Input validation error in HCL Notes - CVE-2020-4089
Published: August 19, 2020
HCL Notes
HCL Technologies
Description
The vulnerability allows a remote attacker to gain access to sensitive information.
The vulnerability exists due to insufficient validation of user-supplied input within the "mailto" URI handler. A remote attacker can trick the victim to click on a specially crafted "mailto" link and attack to the email arbitrary file from the victim's system without any additional warning.