vendor:
LogAnalyzer
by:
Gustavo Sorondo
6.1
CVSS
MEDIUM
Cross-Site Scripting (XSS)
79
CWE
Product Name: LogAnalyzer
Affected Version From: <4.1.7
Affected Version To: <4.1.7
Patch Exists: YES
Related CWE: CVE-2018-19877
CPE: loganalyzer.adiscon.com
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: None
2018
Adiscon LogAnalyzer 4.1.7 – Cross-Site Scripting
Adiscon LogAnalyzer before 4.1.7 is affected by Cross-Site Scripting (XSS) in the 'referer' parameter of the login.php file.
Mitigation:
Update to version 4.1.7.