#VU45779 Input validation error in HCL Notes - CVE-2020-4089

 

#VU45779 Input validation error in HCL Notes - CVE-2020-4089

Published: August 19, 2020


Vulnerability identifier: #VU45779
Vulnerability risk: Medium
CVSSv4.0: CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:U/U:Green
CVE-ID: CVE-2020-4089
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: No public exploit available
Vulnerable software:
HCL Notes
Software vendor:
HCL Technologies

Description

The vulnerability allows a remote attacker to gain access to sensitive information.

The vulnerability exists due to insufficient validation of user-supplied input within the "mailto" URI handler. A remote attacker can trick the victim to click on a specially crafted "mailto" link and attack to the email arbitrary file from the victim's system without any additional warning.


Remediation

Cybersecurity Help is currently unaware of any official solution to address this vulnerability.

External links