CVE-2013-0549 Information

Description

Cross-site scripting (XSS) vulnerability in the Web Content Manager - Web Content Viewer Portlet in the server in IBM WebSphere Portal 7.0.0.x through 7.0.0.2 CF22 and 8.0.0.x through 8.0.0.1 CF5 when the IBM Portlet API is used allows remote attackers to inject arbitrary web script or HTML via a crafted URL.

Reference

http://www-01.ibm.com/support/docview.wss?uid=swg1PM84525 http://www-01.ibm.com/support/docview.wss?uid=swg21638984 https://exchange.xforce.ibmcloud.com/vulnerabilities/82762

Share on: