CVE-2023-37539: Hcltech Domino
Medium severity, CVSS 5.4. EPSS: 0.3% chance of exploitation in the next 30 days.
The Domino Catalog template is susceptible to a Stored Cross-Site Scripting (XSS) vulnerability. An attacker with the ability to edit documents in the catalog application/database created from this template can embed a cross site scripting attack. The attack would be activated by an end user clicking it.
Affected products
- Hcltech Domino: version 11.0 only; version 12.0 only; version 14.0 only
Published 2024-06-06. Last modified 2026-06-17.