VYPR
Medium severity5.4NVD Advisory· Published Feb 1, 2017· Updated May 13, 2026

CVE-2016-5951

CVE-2016-5951

Description

IBM Kenexa LCMS Premier on Cloud 10.3 is vulnerable to stored cross-site scripting, allowing authenticated users to inject arbitrary JavaScript into the Web UI.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

IBM Kenexa LCMS Premier on Cloud 10.3 is vulnerable to stored cross-site scripting, allowing authenticated users to inject arbitrary JavaScript into the Web UI.

Vulnerability

IBM Kenexa LCMS Premier on Cloud version 10.3 is vulnerable to cross-site scripting (XSS). This vulnerability allows authenticated users to embed arbitrary JavaScript code into the Web UI, altering the intended functionality. The issue is addressed in the security bulletin from IBM [1].

Exploitation

An attacker needs authenticated access to the application. With a low-privileged account, the attacker can inject malicious script into input fields or other user-controllable content that is later rendered in the Web UI. The attack requires user interaction, as a victim user with a trusted session must view the manipulated page in their browser [1].

Impact

Successful exploitation can lead to disclosure of the victim's credentials within the trusted session. The attacker can hijack the victim's session or perform other actions on behalf of the victim, with the impact being limited to low confidentiality and low integrity, as per the CVSS vector [1].

Mitigation

IBM has addressed this vulnerability in Kenexa LCMS Premier on Cloud version 10.3. Users should upgrade to version 10.3 or later as specified in the security bulletin [1]. No workarounds are mentioned in the available reference.

AI Insight generated on May 23, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

2

News mentions

0

No linked articles in our index yet.