peter bassill · operator
$ cve CVE-2004-1621 JSON

CVE-2004-1621 EXPLOIT

4.3
MEDIUM · CVSS 2.0 · EPSS 3.1% (pctl 87)

Patch early

A public exploit exists.

Description

NOTE: this issue has been disputed by the vendor. Cross-site scripting (XSS) vulnerability in IBM Lotus Notes R6 and Domino R6, and possibly earlier versions, allows remote attackers to execute arbitrary web script or HTML via square brackets at the beginning and end of (1) computed for display, (2) computed when composed, or (3) computed text element fields. NOTE: the vendor has disputed this issue, saying that it is not a problem with Notes/Domino itself, but with the applications that do not properly handle this feature

Scoring

CVSS4.3 (MEDIUM, v2.0)
VectorAV:N/AC:M/Au:N/C:N/I:P/A:N
EPSS3.08% — more likely to be exploited than 87% of all CVEs
On CISA KEVno
Public exploityes
Published2004-10-18
Last modified2026-06-16

Affected (1)

VendorProduct
ibmlotus domino

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD