Free and open-source vulnerability scanner

Mageni eases for you the vulnerability scanning, assessment, and management process. It is free and open-source.

Install Now

Available for macOS, Windows, and Linux

App screenshot

LiveZilla < 8.0.1.2 Multiple XSS Vulnerabilities

Information

Severity

Severity

Medium

Family

Family

Web application abuses

CVSSv2 Base

CVSSv2 Base

4.3

CVSSv2 Vector

CVSSv2 Vector

AV:N/AC:M/Au:N/C:N/I:P/A:N

Solution Type

Solution Type

Vendor Patch

Created

Created

4 years ago

Modified

Modified

4 years ago

Summary

LiveZilla is prone to multiple cross-site scripting vulnerabilities.

Insight

Insight

LiveZilla is prone to multiple cross-site scripting vulnerabilities: - XSS vulnerability in mobile/index.php via the Accept-Language HTTP header (CVE-2019-12962) - XSS vulnerability in the chat.php Create Ticket Action (CVE-2019-12963) - XSS vulnerability in the ticket.php Subject (CVE-2019-12964)

Affected Software

Affected Software

LiveZilla version 8.0.1.1 and probably prior.

Detection Method

Detection Method

Checks if a vulnerable version is present on the target host.

Solution

Solution

Update to version 8.0.1.2 or later.

Common Vulnerabilities and Exposures (CVE)