PT-2012-2028 · Dojo Foundation+1 · Dojo+1
Published
2012-01-03
·
Updated
2017-08-29
·
CVE-2011-5048
CVSS v2.0
4.3
Medium
| Vector | AV:N/AC:M/Au:N/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
IBM Web Experience Factory versions 7.0 through 7.0.1
Description
The issue allows remote attackers to inject arbitrary web script or HTML via a text INPUT element or TEXTAREA element, related to an interaction between Smart Refresh and Dojo. This can be exploited to conduct cross-site scripting (XSS) attacks.
Recommendations
For IBM Web Experience Factory versions 7.0 through 7.0.1, consider disabling the Smart Refresh feature as a temporary workaround until a patch is available. Restrict access to TEXTAREA and INPUT elements to minimize the risk of exploitation.
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Dojo
Ibm Web Experience Factory