CVE-2010-2277
Multiple cross-site scripting (XSS) vulnerabilities in IBM Lotus Connections 2.5.x before 2.5.0.2 allow remote attackers to inject arbitrary web script or HTML via the (1) create or (2) edit form in the Communities component, the (3) verbiage field in…
Does this matter?
Lower severity and a low EPSS score (1.22%). Track it; it rarely justifies an emergency change on its own.
Description
Multiple cross-site scripting (XSS) vulnerabilities in IBM Lotus Connections 2.5.x before 2.5.0.2 allow remote attackers to inject arbitrary web script or HTML via the (1) create or (2) edit form in the Communities component, the (3) verbiage field in the Bookmarks component, or (4) unspecified vectors related to the Mobile Blogs component.
- CVSS 2.0
- 4.3 MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
- EPSS
- 1.22% probability · 67th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-79
- Affected
- ibm/lotus connections
- Source
- cve@mitre.org
References
- http://secunia.com/advisories/40007Vendor Advisory
- http://www-01.ibm.com/support/docview.wss?uid=swg21431472Patch, Vendor Advisory
- http://www-1.ibm.com/support/docview.wss?uid=swg1LO47214
- http://www-1.ibm.com/support/docview.wss?uid=swg1LO47362
- http://www-1.ibm.com/support/docview.wss?uid=swg1LO47921
- http://www.vupen.com/english/advisories/2010/1281Patch, Vendor Advisory
- http://secunia.com/advisories/40007Vendor Advisory
- http://www-01.ibm.com/support/docview.wss?uid=swg21431472Patch, Vendor Advisory
- http://www-1.ibm.com/support/docview.wss?uid=swg1LO47214
- http://www-1.ibm.com/support/docview.wss?uid=swg1LO47362
- http://www-1.ibm.com/support/docview.wss?uid=swg1LO47921
- http://www.vupen.com/english/advisories/2010/1281Patch, Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.