Cross-Site Scripting in IBM Domino Web Server Affecting Multiple Versions
CVE-2015-1981

Currently unrated

Key Information:

Vendor
IBM
Status
Vendor
CVE Published:
28 June 2015

Summary

A cross-site scripting (XSS) vulnerability exists in the web server of IBM Domino 8.5.x prior to version 8.5.3 FP6 IF8 and 9.x prior to version 9.0.1 FP4 when Webmail is enabled. This flaw allows remote authenticated users to inject arbitrary web scripts or HTML into the web application via specially crafted URLs, potentially leading to unauthorized actions or data exposure. The issue underscores the importance of proper input validation and sanitization mechanisms in web applications to prevent XSS attacks.

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.