CVE
- Id
- 95740
- CVE No.
- CVE-2016-8920
- Status
- Candidate
- Description
- IBM Kenexa LMS on Cloud 13.1 and 13.2 - 13.2.4 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
- Phase
- Assigned (20161025)
- Votes
- None (candidate not yet proposed)
- Comments