CVE-2026-40457 Details
Description
A Reflected Cross-Site Scripting (XSS) vulnerability exists in LMS (LAN Management System) before commit 9c5651b in the "dbrecover.php" and "netremap.php" modules where unsanitized GET parameters are directly embedded into HTML output. This allows an attacker to inject arbitrary JavaScript when an authenticated user clicks a crafted link, provided the required conditions (such as a network defined in the system) are met.
A reflected cross-site scripting vulnerability has been identified in LAN Management System (LMS) versions prior to commit 9c5651b. The issue resides in the 'dbrecover.php' and 'netremap.php' modules, where unsanitized GET parameters are directly inserted into the HTML output. This vulnerability allows an attacker to inject arbitrary JavaScript, which is executed when an authenticated user clicks on a crafted link, provided certain conditions, such as the presence of a defined network in the system, are met.
Users can update to LMS version 27 or later, where this vulnerability has been addressed.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Jun 18, 2026CISA-ADP
Assessed Jun 18, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://cert.pl/posts/2026/06/CVE-2026-40455 | [email protected] | AdvisoryBundleRemedy |
| https://github.com/chilek/lms/commit/9c5651b39bfd086cc34fc9a78ddaa8c0815af114 | [email protected] | Source CodeVendor |
| https://lms.org.pl/ | [email protected] | Vendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-79 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| LMS | < 9c5651b |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 18, 2026 | New CVE Received | [email protected] |
| Jun 18, 2026 | CVE Modified | CISA-ADP |
Volerion