IBM Informix Dynamic Server 12.10 and 14.10 is vulnerable to HTML injection. A remote attacker could inject malicious HTML code, which when viewed, would be executed in the victim's Web browser within the security context of the hosting site.
History

Mon, 28 Jul 2025 18:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 28 Jul 2025 15:45:00 +0000

Type Values Removed Values Added
Description IBM Informix Dynamic Server 12.10 and 14.10 is vulnerable to HTML injection. A remote attacker could inject malicious HTML code, which when viewed, would be executed in the victim's Web browser within the security context of the hosting site.
Title IBM Informix Dynamic Server HTML injection
First Time appeared Ibm
Ibm informix Dynamic Server
Weaknesses CWE-80
CPEs cpe:2.3:a:ibm:informix_dynamic_server:12.10:-:*:*:-:*:*:*
cpe:2.3:a:ibm:informix_dynamic_server:14.10:*:*:*:*:*:*:*
Vendors & Products Ibm
Ibm informix Dynamic Server
References
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published: 2025-07-28T15:27:37.588Z

Updated: 2025-07-28T17:20:17.395Z

Reserved: 2024-10-14T12:05:13.492Z

Link: CVE-2024-49343

cve-icon Vulnrichment

Updated: 2025-07-28T17:20:13.167Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-07-28T16:15:24.433

Modified: 2025-07-29T14:14:29.590

Link: CVE-2024-49343

cve-icon Redhat

No data.