CVE-2013-4064

Cross-site scripting (XSS) vulnerability in iNotes in IBM Domino 8.5.x before 8.5.3 FP6 and 9.0.x before 9.0.1, when ultra-light mode is enabled, allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors, aka SPR PTHN9ARMFA.
Cross-site Scripting
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
2.1 UNKNOWN
NETWORK
HIGH
AV:N/AC:H/Au:S/C:N/I:P/A:N
ibmCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 38%
VendorProductVersion
ibmlotus_domino
8.5.3.0
ibmlotus_domino
8.5.3.1
ibmlotus_domino
8.5.3.2
ibmlotus_domino
8.5.3.3
ibmlotus_domino
8.5.3.4
ibmlotus_domino
8.5.3.5
ibmlotus_domino
9.0.0.0
ibmlotus_inotes
8.5.3.0
ibmlotus_inotes
8.5.3.1
ibmlotus_inotes
8.5.3.2
ibmlotus_inotes
8.5.3.3
ibmlotus_inotes
8.5.3.4
ibmlotus_inotes
8.5.3.5
ibmlotus_inotes
9.0.0.0
𝑥
= Vulnerable software versions