Cross-Site Scripting Vulnerability in IBM Campaign Product
CVE-2017-1114
5.4MEDIUM
What is CVE-2017-1114?
IBM Campaign versions 9.1, 9.1.2, and 10 are susceptible to a cross-site scripting vulnerability. This flaw allows attackers to inject arbitrary JavaScript into the Web UI, which can manipulate the application's functionality and potentially lead to the disclosure of sensitive user credentials in a trusted session. This poses a significant risk to users, emphasizing the necessity for prompt remediation to safeguard affected systems.
Affected Version(s)
Campaign 9.1
Campaign 9.1.2
Campaign 10