Back to Database
Status published
Medium
CVE-2019-18955
The web console in Lansweeper 7.2.105.2 has XSS via the...
Vulnerability Description
The web console in Lansweeper 7.2.105.2 has XSS via the URL path. Product vulnerability has been fixed and disclosed within changelog as of 02 Dec 2019.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2019-18955
Credits & Attribution
No credits recorded in the NVD database.
References
More from lansweeper
View All →CVE-2020-14011
Lansweeper 6.0.x through 7.2.x has a default installation in which...
Critical
9.8
CVE-2020-13658
In Lansweeper 8.0.130.17, the web console is vulnerable to a...
High
8
CVE-2019-13462
Lansweeper before 7.1.117.4 allows unauthenticated SQL injection....
Critical
9.1
CVE-2017-9292
Lansweeper before 6.0.0.65 has XSS in an image retrieval URI,...
Medium
6.1
CVE-2017-16841
LanSweeper 6.0.100.75 has XSS via the description parameter to /Calendar/CalendarActions.aspx....
Medium
6.1
Affected Vendor
lansweeper
View all reports →Affected Software
lansweeper
Vulnerable Versions:
7.2.105.2
Timeline
Official Publish:
December 19th, 2019
Last Modified:
August 5th, 2024
Added to House:
July 20th, 2026
CVSS Vectors
V3:
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.