Description
IBM Kenexa LMS on Cloud is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
Affected products
- IBM Corporation / Kenexa LMS on Cloud13.0 – 13.0
- IBM Corporation / Kenexa LMS on Cloud13.1 – 13.1
- IBM Corporation / Kenexa LMS on Cloud13.2 – 13.2
- IBM Corporation / Kenexa LMS on Cloud13.2.2 – 13.2.2
- IBM Corporation / Kenexa LMS on Cloud13.2.3 – 13.2.3
- IBM Corporation / Kenexa LMS on Cloud13.2.4 – 13.2.4
- IBM Corporation / Kenexa LMS on Cloud14.0.0 – 14.0.0
- IBM Corporation / Kenexa LMS on Cloud14.1.0 – 14.1.0
- IBM Corporation / Kenexa LMS on Cloud14.2.0 – 14.2.0