Cross-site scripting in IBM BladeCenter Advanced Management Module - CVE-2013-4007
Published: May 22, 2024
IBM BladeCenter Advanced Management Module
IBM Corporation
Description
The disclosed vulnerability allows a remote attacker to perform cross-site scripting (XSS) attacks.
The vulnerability exists due to insufficient sanitization of user-supplied data. A remote attacker can exploit this vulnerability to execute a script in a victim's web browser within the security context of the hosting web site, once the URL is clicked, to steal the victim's cookie-based authentication credentials.