First published: Wed Dec 19 2012(Updated: )
Multiple cross-site scripting (XSS) vulnerabilities in IBM Lotus Foundations Start before 1.2.2c allow remote authenticated users to inject arbitrary web script or HTML via a Webconfig Users user-attribute field, as demonstrated by the (1) First Name or (2) Last Name field.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Lotus Foundations Start | <=1.2.2 | |
IBM Lotus Foundations Start | =1.0 | |
IBM Lotus Foundations Start | =1.1 | |
IBM Lotus Foundations Start | =1.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.