vendor:
WebSphere Portal
by:
Filippo Roncari
5.5
CVSS
MEDIUM
Stored Cross-Site Scripting
79
CWE
Product Name: WebSphere Portal
Affected Version From: 6.1.2000
Affected Version To: 7
Patch Exists: NO
Related CWE: CVE-2014-0910
CPE: a:ibm:websphere_portal
Platforms Tested:
2014
IBM WebSphere Portal Stored Cross-Site Scripting Vulnerability [CVE-2014-0910]
IBM WebSphere Portal is prone to a stored Cross-Site Scripting (XSS) vulnerability in the Web Content Management component, which allows authenticated users to inject arbitrary JavaScript. A potential attacker authenticated to the Web Content Management can exploit this vulnerability by creating a malicious web content and persuading the victim to visit it. This issue can lead to different kind of user-targeted attacks such as cookie stealing and account violation.
Mitigation:
Unknown