Cross-Site Scripting Vulnerabilities in IBM iNotes
CVE-2013-0525 
Currently unrated
What is CVE-2013-0525?
Multiple cross-site scripting vulnerabilities in IBM iNotes 8.5.x enable local users to inject arbitrary web scripts or HTML into a shared mail file. This can lead to unauthorized content being executed in the context of other users, allowing potential attackers to manipulate the web interface, steal sensitive information, or perform actions on behalf of the unsuspecting users.