CVE 5.4 MEDIUM

HTML Injection Vulnerability in a Specific URL Endpoint of the IBM OpenPages Application_CVE-2025-36121

5.4 / 10
MEDIUM
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

Description

IBM OpenPages 9.1 and 9.0 is vulnerable to HTML injection. A remotely authenticated attacker could inject malicious HTML code, which when viewed, would be executed in the victim's Web browser within the security context of the hosting site.

Basic Information

ID CVE-2025-36121
Source ibm
Published Oct 27, 2025 at 14:56
Modified Oct 27, 2025 at 18:51

Affected Product

Vendor IBM
Product OpenPages
Version 9.1
Affected Versions IBM OpenPages 9.1
IBM OpenPages 9.0

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.