First published: Tue Apr 23 2013(Updated: )
Cross-site scripting (XSS) vulnerability in the Bookmarks component in IBM Lotus Connections before 4.0 CR3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Connections | <=4.0.0.0 | |
IBM Connections | =1.0.0.0 | |
IBM Connections | =1.0.1.0 | |
IBM Connections | =1.0.2.0 | |
IBM Connections | =2.0.0.0 | |
IBM Connections | =2.0.1.0 | |
IBM Connections | =2.0.1.1 | |
IBM Connections | =2.5.0.1 | |
IBM Connections | =2.5.0.2 | |
IBM Connections | =2.5.0.3 | |
IBM Connections | =3.0.0.0 | |
IBM Connections | =3.0.1.0 | |
IBM Connections | =3.0.1.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2013-0503 is considered to be a medium severity cross-site scripting vulnerability.
To fix CVE-2013-0503, upgrade IBM Lotus Connections to version 4.0 CR3 or later.
CVE-2013-0503 allows remote attackers to inject arbitrary web scripts or HTML into the application.
IBM Lotus Connections versions prior to 4.0 CR3, and several earlier versions including 1.0.x and 2.x series are affected.
Exploiting CVE-2013-0503 can lead to unauthorized access and manipulation of content by injecting malicious web scripts.