vendor:
LanSweeper
by:
Miguel Mendez Z
6,1
CVSS
MEDIUM
Cross Site Scripting and HTMLi
79
CWE
Product Name: LanSweeper
Affected Version From: 6.0.100.75
Affected Version To: 6.0.100.75
Patch Exists: Yes
Related CWE: CVE-2017-16841
CPE: a:lansweeper:lansweeper
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: None
2017
Vulnerability in LanSweeper
LanSweeper 6.0.100.75 has XSS via the description parameter to "/Calendar/CalendarActions.aspx". Take control of the browser using the xss shell or perform malware attacks on users.
Mitigation:
Vendor contacted, patch available