Cross-Site Scripting in IBM Domino Web Server Affecting Multiple Versions
CVE-2015-1981

Currently unrated

Key Information:

Vendor

IBM

Status
Vendor
CVE Published:
28 June 2015

What is CVE-2015-1981?

A cross-site scripting (XSS) vulnerability exists in the web server of IBM Domino 8.5.x prior to version 8.5.3 FP6 IF8 and 9.x prior to version 9.0.1 FP4 when Webmail is enabled. This flaw allows remote authenticated users to inject arbitrary web scripts or HTML into the web application via specially crafted URLs, potentially leading to unauthorized actions or data exposure. The issue underscores the importance of proper input validation and sanitization mechanisms in web applications to prevent XSS attacks.

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.