CVE-2025-33110
BaseFortify
Publication date: 2025-11-06
Last updated on: 2025-11-24
Assigner: IBM Corporation
Description
Description
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| ibm | openpages | 9.0.0 |
| ibm | openpages | 9.1.0 |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-80 | The product receives input from an upstream component, but it does not neutralize or incorrectly neutralizes special characters such as "<", ">", and "&" that could be interpreted as web-scripting elements when they are sent to a downstream component that processes web pages. |
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?
IBM OpenPages versions 9.1 and 9.0 with Watson have a vulnerability to HTML injection. This means a remote attacker can insert malicious HTML code that, when viewed by a user, executes within the user's web browser under the security context of the hosting site.
How can this vulnerability impact me? :
This vulnerability can allow an attacker to execute malicious HTML code in the victim's browser, potentially leading to unauthorized actions, data theft, or manipulation of the web application as the attacker gains the same privileges as the hosting site within the browser.