Description
IBM Jazz Team Server based Applications are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 182397.
Remediation
References
Related Vulnerabilities
Dotclear Unrestricted Upload of File with Dangerous Type Vulnerability (CVE-2016-7902)
WordPress Plugin WC Duplicate Order Security Bypass (1.5)
WordPress Plugin WP-HR Manager:The Human Resources Unspecified Vulnerability (2.9.4)
WordPress Plugin WP Private Message Insecure Direct Object Reference (1.0.5)
Craft CMS Weak Password Recovery Mechanism for Forgotten Password Vulnerability (CVE-2022-29933)