CVE
Vendors
Products
Updated
CVSS v2
CVSS v3
IBM Rational Collaborative Lifecycle Management 6.0 through 6.0.6.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 148614.
In Zoho ManageEngine AssetExplorer, a Stored XSS vulnerability was discovered in the 6.2.0 version via the /AssetDef.do ciName or assetName parameter.
In the 5.4.0 version of the Fork CMS software, HTML Injection and Stored XSS vulnerabilities were discovered via the /backend/ajax URI.
AirTies Air 5443v2 devices with software 1.0.0.18 have XSS via the top.html productboardtype parameter.
AirTies Air 5453 devices with software 1.0.0.18 have XSS via the top.html productboardtype parameter.
AirTies Air 5343v2 devices with software 1.0.0.18 have XSS via the top.html productboardtype parameter.
AirTies Air 5442 devices with software 1.0.0.18 have XSS via the top.html productboardtype parameter.
IBM Rational Quality Manager 5.0 through 6.0.6 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 148613.
AirTies Air 5650 devices with software 1.0.0.18 have XSS via the top.html productboardtype parameter.
AirTies Air 5021 devices with software 1.0.0.18 have XSS via the top.html productboardtype parameter.
