Multiple Cross-Site Scripting Vulnerabilities in IBM Lotus Sametime
CVE-2011-1038
Currently unrated
Summary
IBM Lotus Sametime 8.0.1 contains multiple cross-site scripting vulnerabilities that can be exploited by remote attackers. Malicious actors can inject arbitrary web scripts or HTML code through the messageString parameter in a WebMessage action or via the PATH_INFO. This allows them to execute harmful scripts in the context of the user’s session, posing significant security risks.
References
Timeline
Vulnerability published
Vulnerability Reserved