Cross-Site Scripting in IBM TS4500 Web GUI
CVE-2025-36088
5.4MEDIUM
What is CVE-2025-36088?
The IBM TS4500 web GUI versions 1.10.00-F00 and 1.11.0.0-D00 through 1.11.0.2-C00 are susceptible to a cross-site scripting vulnerability. This issue allows an authenticated user to inject arbitrary JavaScript code into the web interface. The consequence is a potential alteration of the intended functionality, which could result in unauthorized access to user credentials during a trusted session. Users are encouraged to apply available patches to mitigate this risk.
Affected Version(s)
Storage TS4500 Library 1.11.0.0-D00
Storage TS4500 Library 1.11.0.1-C00
Storage TS4500 Library 1.11.0.2-C00