First published: Wed Aug 29 2018(Updated: )
IBM Campaign 9.1, 9.1.2, and 10 is vulnerable to HTML injection. A remote attacker could inject malicious HTML code, which when viewed, would be executed in the victim's Web browser within the security context of the hosting site. IBM X-Force ID: 121153.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Campaign | =9.1 | |
IBM Campaign | =9.1.2 | |
IBM Campaign | =10.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-1115 is rated as a medium severity vulnerability due to its potential for HTML injection attacks.
To fix CVE-2017-1115, update IBM Campaign to versions 9.1.2 or 10.0 or apply available patches.
CVE-2017-1115 affects users of IBM Campaign versions 9.1, 9.1.2, and 10.0.
CVE-2017-1115 is an HTML injection vulnerability allowing remote attackers to execute malicious code.
The potential impacts of CVE-2017-1115 include session hijacking, data theft, and unauthorized actions taken within the context of the affected site.