Vulnerability Description
LogMeIn LastPass through 4.15.0 allows remote attackers to cause a denial of service (browser hang) via an HTML document because the resource consumption of onloadwff.js grows with the number of INPUT elements.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Logmein | Lastpass | <= 4.15.0 |
Related Weaknesses (CWE)
References
- https://forums.lastpass.com/viewtopic.php?f=12&t=286955Issue TrackingThird Party Advisory
- https://twitter.com/LastPassHelp/status/955478245650071552Issue TrackingThird Party Advisory
- https://www.youtube.com/watch?v=wTcYWZwq3TEExploitThird Party Advisory
- https://forums.lastpass.com/viewtopic.php?f=12&t=286955Issue TrackingThird Party Advisory
- https://twitter.com/LastPassHelp/status/955478245650071552Issue TrackingThird Party Advisory
- https://www.youtube.com/watch?v=wTcYWZwq3TEExploitThird Party Advisory
FAQ
What is CVE-2018-10193?
CVE-2018-10193 is a vulnerability with a CVSS score of 7.5 (HIGH). LogMeIn LastPass through 4.15.0 allows remote attackers to cause a denial of service (browser hang) via an HTML document because the resource consumption of onloadwff.js grows with the number of INPUT...
How severe is CVE-2018-10193?
CVE-2018-10193 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2018-10193?
Check the references section above for vendor advisories and patch information. Affected products include: Logmein Lastpass.