Reflected Cross-Site Scripting in LAN Management System by Chilek
CVE-2026-40457
2.1LOW
What is CVE-2026-40457?
A Reflected Cross-Site Scripting (XSS) vulnerability exists in the LAN Management System (LMS) prior to commit 9c5651b. The issue lies in the 'dbrecover.php' and 'netremap.php' modules, where unsanitized GET parameters are used directly in HTML output. This flaw allows an attacker to craft a malicious link that, when clicked by an authenticated user, injects arbitrary JavaScript into the user's session, potentially compromising user data and session integrity.
Affected Version(s)
LMS 0 < 9c5651b
