First published: Tue Nov 25 2008(Updated: )
Cross-site scripting (XSS) vulnerability in IBM Workplace Content Management (WCM) 6.0G and 6.1 before CF8, when a Page Navigation Component shows menu entries, allows remote attackers to inject arbitrary web script or HTML via unspecified parameters in the URI, related to parameters "not being encoded."
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Workplace Web Content Management | =6.0 | |
IBM Workplace Web Content Management | =6.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2008-5228 has a medium severity rating as it allows attackers to perform cross-site scripting (XSS) attacks.
To mitigate CVE-2008-5228, users should upgrade to IBM Workplace Content Management version 6.0 or 6.1 with the appropriate patches that address this vulnerability.
CVE-2008-5228 affects IBM Workplace Content Management versions 6.0G and 6.1 prior to CF8.
Attackers exploiting CVE-2008-5228 can inject arbitrary web scripts or HTML into the application, potentially compromising user data or conducting phishing attacks.
Yes, user data may be at risk because the XSS vulnerability can lead to session hijacking, data manipulation, or exposure of sensitive information.