PT-2021-19486 · Adiscon · Loganalyzer
Michael Strametz
·
Published
2021-06-08
·
Updated
2021-06-11
·
CVE-2021-31738
CVSS v3.1
6.1
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Adiscon LogAnalyzer versions 4.1.10 through 4.1.11
Description
The issue allows for XSS in the login.php file.
Recommendations
For versions 4.1.10 and 4.1.11, consider disabling access to the
login.php file until a fix is available.Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Loganalyzer