PT-2011-1703 · Lightneasy · Lightneasy

Published

2011-03-01

·

Updated

2011-04-21

·

CVE-2010-4753

CVSS v2.0

4.3

Medium

VectorAV:N/AC:M/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions LightNEasy version 3.2.1
Description A cross-site scripting (XSS) issue exists due to improper handling of the id parameter in a forced SQL error message, allowing remote attackers to inject arbitrary web script or HTML.
Recommendations For version 3.2.1, avoid using the id parameter in the affected LightNEasy.php file until a proper fix is applied to handle it securely. As a temporary workaround, consider restricting access to the LightNEasy.php file to minimize the risk of exploitation.

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2010-4753

Affected Products

Lightneasy