Reflected Cross-Site Scripting in LAN Management System by Chilek
CVE-2026-40457

2.1LOW

Key Information:

Vendor

Lms

Status
Vendor
CVE Published:
18 June 2026

What is CVE-2026-40457?

A Reflected Cross-Site Scripting (XSS) vulnerability exists in the LAN Management System (LMS) prior to commit 9c5651b. The issue lies in the 'dbrecover.php' and 'netremap.php' modules, where unsanitized GET parameters are used directly in HTML output. This flaw allows an attacker to craft a malicious link that, when clicked by an authenticated user, injects arbitrary JavaScript into the user's session, potentially compromising user data and session integrity.

Affected Version(s)

LMS 0 < 9c5651b

References

CVSS V4

Score:
2.1
Severity:
LOW
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Tymoteusz Dominik
.