vendor:
LogAnalyzer
by:
Pedro (ISSDU TW)
6.1
CVSS
MEDIUM
Cross Site Scripting
79
CWE
Product Name: LogAnalyzer
Affected Version From: v4.1.0
Affected Version To: v4.1.13
Patch Exists: NO
Related CWE: CVE-2023-36306
CPE: loganalyzer.adiscon.com
Platforms Tested: Linux
2023
Adiscon LogAnalyzer v.4.1.13 – Cross Site Scripting
The Adiscon LogAnalyzer version 4.1.13 and earlier is vulnerable to cross-site scripting (XSS) attacks. The vulnerability allows an attacker to inject malicious scripts into certain URLs, leading to potential XSS attacks. The issue exists in various pages of the application, such as 'asktheoracle.php', 'chartgenerator.php', 'details.php', 'index.php', 'search.php', 'export.php', 'reports.php', and 'statistics.php'. By exploiting this vulnerability, an attacker can execute arbitrary scripts in the context of the user's browser, potentially leading to session hijacking, information theft, or other malicious actions.
Mitigation:
To mitigate this vulnerability, it is recommended to update the Adiscon LogAnalyzer software to a version that includes a patch for this issue. Additionally, users should be cautious when clicking on unknown or suspicious URLs.