← Vulnerability feed

Vulnerability record · CVE-2013-0592 · published 11 July 2018

CVE-2013-0592: Ibm inotes cross-site scripting vulnerability

Ibm · Inotes

Cross-site scripting (XSS) vulnerability in IBM iNotes before 8.5.3 Fix Pack 6 and 9.x before 9.0.1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. IBM X-Force ID: 83815.

5.4 CVSS 3.0 Medium EPSS 0.70% · top 48.4% CWE-79 · Cross-site scripting
5.4CVSS 3.0 base score, v2 3.5
0.70%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
4References
16 Jun 2026Last modified by NVD

Description

Cross-site scripting (XSS) vulnerability in IBM iNotes before 8.5.3 Fix Pack 6 and 9.x before 9.0.1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. IBM X-Force ID: 83815.

CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2013-0592 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

7.5CVE-2013-0589Ibm inotes information exposure vulnerabilityIBM iNotes before 8.5.3 Fix Pack 6 and 9.x before 9.0.1 allows remote attackers to bypass the remote image filtering mechanism and obtain sensitive i…EPSS 1.7%6.5CVE-2017-1130Ibm inotes vulnerabilityIBM Notes 8.5 and 9.0 is vulnerable to a denial of service. If a user is persuaded to click on a malicious link, it would open up many file select di…EPSS 29%6.5CVE-2017-1129Ibm inotes vulnerabilityIBM Notes 8.5 and 9.0 is vulnerable to a denial of service. If a user is persuaded to click on a malicious link, it could cause the Notes client to h…EPSS 30%6.1CVE-2017-1659Ibm inotes cross-site scripting vulnerability"HCL iNotes is susceptible to a Cross-Site Scripting (XSS) Vulnerability. An attacker could use this vulnerability to steal the victim's cookie-based…EPSS 0.67%6.1CVE-2013-0594Ibm inotes open redirect vulnerabilityOpen redirect vulnerability in IBM iNotes before 8.5.3 Fix Pack 6 and 9.x before 9.0.1 allows remote attackers to redirect users to arbitrary web sit…EPSS 1.3%6.1CVE-2017-1421Ibm inotes cross-site scripting vulnerabilityIBM iNotes is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the …EPSS 1.1%6.1CVE-2017-1327Ibm inotes cross-site scripting vulnerabilityIBM iNotes 8.5 and 9.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus a…EPSS 0.97%6.1CVE-2017-1332Ibm inotes cross-site scripting vulnerabilityIBM iNotes 8.5 and 9.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus a…EPSS 0.98%

Source: NIST National Vulnerability Database (record CVE-2013-0592), CISA KEV, FIRST EPSS (scores of 2026-10-06). This page is refreshed as NVD updates the record.