Vulnerability Description
A Reflected Cross-Site Scripting (XSS) vulnerability exists in LMS (LAN Management System) before commit 9c5651b in the "dbrecover.php" and "netremap.php" modules where unsanitized GET parameters are directly embedded into HTML output. This allows an attacker to inject arbitrary JavaScript when an authenticated user clicks a crafted link, provided the required conditions (such as a network defined in the system) are met.
Related Weaknesses (CWE)
References
- https://cert.pl/posts/2026/06/CVE-2026-40455
- https://github.com/chilek/lms/commit/9c5651b39bfd086cc34fc9a78ddaa8c0815af114
- https://lms.org.pl/
FAQ
What is CVE-2026-40457?
CVE-2026-40457 is a documented vulnerability. A Reflected Cross-Site Scripting (XSS) vulnerability exists in LMS (LAN Management System) before commit 9c5651b in the "dbrecover.php" and "netremap.php" modules where unsanitized GET parameters are ...
How severe is CVE-2026-40457?
CVSS scoring is not yet available for CVE-2026-40457. Check NVD for updates.
Is there a patch for CVE-2026-40457?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.