The web console in Lansweeper 7.2.105.2 has XSS via the URL path. Product vulnerability has been fixed and disclosed within changelog as of 02 Dec 2019.
References
Link | Resource |
---|---|
https://www.lansweeper.com/changelog/ | Release Notes |
Configurations
Information
Published : 2019-12-19 09:15
Updated : 2019-12-27 09:58
NVD link : CVE-2019-18955
Mitre link : CVE-2019-18955
JSON object : View
CWE
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Products Affected
lansweeper
- lansweeper