Cross-site Scripting Flaw in LOYTEC LVIS-3ME Web Interface
CVE-2017-13994

6.1MEDIUM

Key Information:

Vendor

Loytec

Vendor
CVE Published:
5 October 2017

What is CVE-2017-13994?

A Cross-site Scripting vulnerability has been found in the web interface of LOYTEC LVIS-3ME. Due to inadequate validation of web requests, the issue allows attackers to execute malicious scripts in the browser of an authenticated user. This occurs when the user is deceived into clicking on a harmful link, potentially compromising sensitive information or granting unauthorized access.

Affected Version(s)

LOYTEC LVIS-3ME LOYTEC LVIS-3ME

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.