Cross-site Scripting Vulnerability in IBM Lotus Sametime Chat Client
CVE-2008-0354

Currently unrated

Key Information:

Vendor
IBM
Vendor
CVE Published:
18 January 2008

Summary

A cross-site scripting vulnerability exists in the chat client of IBM Lotus Sametime versions 7.5 and 7.5.1. This vulnerability allows user-assisted remote attackers to inject arbitrary web scripts or HTML via a specially crafted message. The malicious script executes when a victim hovers their mouse over the compromised message, potentially leading to unauthorized actions on behalf of the user and exposing sensitive information.

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.