CVE-2013-0525: IBM Lotus Inotes

Low severity, CVSS 1.5. EPSS: 0.3% chance of exploitation in the next 30 days.

Multiple cross-site scripting (XSS) vulnerabilities in IBM iNotes 8.5.x allow local users to inject arbitrary web script or HTML via a shared mail file, aka SPR DKEN8PDNTX.

Affected products

  • IBM Lotus Inotes: version 8.5.0.0 only; version 8.5.0.1 only; version 8.5.1.0 only; version 8.5.1.1 only; version 8.5.1.2 only; version 8.5.1.3 only; …

Published 2013-03-26. Last modified 2026-06-16.