HTML Injection Vulnerability in IBM Curam Social Program Management
CVE-2018-1671
6.1MEDIUM
Summary
The IBM Curam Social Program Management 7.0.3 is susceptible to HTML injection attacks. This vulnerability allows remote attackers to craft and inject malicious HTML code into the web application. When a victim views a compromised page, the injected code executes within their web browser, potentially leading to unauthorized actions and data exposure under the security context of the hosting site. This highlights the importance of securing web applications against injection flaws.
References
CVSS V3.1
Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved