Multiple Cross-Site Scripting Vulnerabilities in IBM Lotus Sametime
CVE-2011-1038

Currently unrated

Key Information:

Vendor
IBM
Vendor
CVE Published:
22 February 2011

Summary

IBM Lotus Sametime 8.0.1 contains multiple cross-site scripting vulnerabilities that can be exploited by remote attackers. Malicious actors can inject arbitrary web scripts or HTML code through the messageString parameter in a WebMessage action or via the PATH_INFO. This allows them to execute harmful scripts in the context of the user’s session, posing significant security risks.

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.