CVE-2010-2277

Severity CVSS v4.0:
Pending analysis
Type:
CWE-79 Cross-Site Scripting (XSS)
Publication date:
15/06/2010
Last modified:
11/04/2025

Description

Multiple cross-site scripting (XSS) vulnerabilities in IBM Lotus Connections 2.5.x before 2.5.0.2 allow remote attackers to inject arbitrary web script or HTML via the (1) create or (2) edit form in the Communities component, the (3) verbiage field in the Bookmarks component, or (4) unspecified vectors related to the Mobile Blogs component.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:ibm:lotus_connections:2.5.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:lotus_connections:2.5.0.1:*:*:*:*:*:*:*