Cross-Site Scripting in IBM Domino Web Server Affecting Multiple Versions
CVE-2015-1981
Currently unrated
Summary
A cross-site scripting (XSS) vulnerability exists in the web server of IBM Domino 8.5.x prior to version 8.5.3 FP6 IF8 and 9.x prior to version 9.0.1 FP4 when Webmail is enabled. This flaw allows remote authenticated users to inject arbitrary web scripts or HTML into the web application via specially crafted URLs, potentially leading to unauthorized actions or data exposure. The issue underscores the importance of proper input validation and sanitization mechanisms in web applications to prevent XSS attacks.
References
Timeline
Vulnerability published
Vulnerability Reserved