PT-2012-2028 · Dojo Foundation+1 · Dojo+1

Published

2012-01-03

·

Updated

2017-08-29

·

CVE-2011-5048

CVSS v2.0

4.3

Medium

VectorAV:N/AC:M/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions IBM Web Experience Factory versions 7.0 through 7.0.1
Description The issue allows remote attackers to inject arbitrary web script or HTML via a text INPUT element or TEXTAREA element, related to an interaction between Smart Refresh and Dojo. This can be exploited to conduct cross-site scripting (XSS) attacks.
Recommendations For IBM Web Experience Factory versions 7.0 through 7.0.1, consider disabling the Smart Refresh feature as a temporary workaround until a patch is available. Restrict access to TEXTAREA and INPUT elements to minimize the risk of exploitation.

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2011-5048

Affected Products

Dojo
Ibm Web Experience Factory