CVE-2012-3302

IBM Lotus Domino <8.5.4 - XSS

Title source: llm

Description

Multiple cross-site scripting (XSS) vulnerabilities in IBM Lotus Domino 7.x and 8.x before 8.5.4 allow remote attackers to inject arbitrary web script or HTML via (1) a URL accessed during use of the Mail template in the WebMail UI or (2) a URL accessed during use of Domino Help through the Domino HTTP server.

Scores

EPSS 0.0027
EPSS Percentile 49.9%

Classification

CWE
CWE-79
Status published

Affected Products (25)

ibm/lotus_domino
ibm/lotus_domino
ibm/lotus_domino
ibm/lotus_domino
ibm/lotus_domino
ibm/lotus_domino
ibm/lotus_domino
ibm/lotus_domino
ibm/lotus_domino
ibm/lotus_domino
ibm/lotus_domino
ibm/lotus_domino
ibm/lotus_domino
ibm/lotus_domino
ibm/lotus_domino
... and 10 more

Timeline

Published Aug 21, 2012
Tracked Since Feb 18, 2026