VulnerabilityModified
CVE-2019-18955
The web console in Lansweeper 7.2.105.2 has XSS via the URL path.
MEDIUM 6.1EPSS 0.64%
Does this matter?
Lower severity and a low EPSS score (0.64%). Track it; it rarely justifies an emergency change on its own.
Description
The web console in Lansweeper 7.2.105.2 has XSS via the URL path. Product vulnerability has been fixed and disclosed within changelog as of 02 Dec 2019.
- CVSS 3.1
- 6.1 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
- EPSS
- 0.64% probability · 49th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-79
- Affected
- lansweeper/lansweeper
- Source
- cve@mitre.org
References
- https://www.lansweeper.com/changelog/Release Notes
- https://www.lansweeper.com/changelog/Release Notes
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.