HTML Injection Vulnerability in IBM OpenPages GRC Platform
CVE-2016-3049
5.4MEDIUM
Summary
The IBM OpenPages GRC Platform versions 7.1, 7.2, and 7.3 are susceptible to an HTML injection flaw. This vulnerability allows remote attackers to inject malicious HTML code into the application. If a user subsequently views the compromised content, the embedded code could be executed within the browser’s security context of the hosting site, potentially leading to unauthorized actions or information disclosure. For further details, refer to IBM X-Force ID: 114712.
References
CVSS V3.1
Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved