CVE-2017-5157: XSS
An issue was discovered in Schneider Electric homeLYnk Controller, LSS100100, all versions prior to V1.5.0. The homeLYnk controller is susceptible to a cross-site scripting attack. User inputs can be manipulated to cause execution of JavaScript code.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Schneider Electric homeLYnk Controller (LSS100100)to a version that resolves this vulnerability.Fixed in V1.5.0
Event History
Frequently Asked Questions
What is the severity of CVE-2017-5157?
CVE-2017-5157 is classified as a high-severity vulnerability due to its potential to allow cross-site scripting attacks.
How do I fix CVE-2017-5157?
To fix CVE-2017-5157, upgrade the Schneider Electric homeLYnk Controller to version 1.5.0 or later.
What type of attack does CVE-2017-5157 allow?
CVE-2017-5157 allows for cross-site scripting attacks by manipulating user inputs.
Which software versions are affected by CVE-2017-5157?
CVE-2017-5157 affects all versions of the Schneider Electric homeLYnk Controller prior to version 1.5.0.
Who is impacted by CVE-2017-5157?
Users of the Schneider Electric homeLYnk Controller LSS100100 firmware versions before 1.5.0 are impacted by CVE-2017-5157.