Vulnerability Details CVE-2017-5157
An issue was discovered in Schneider Electric homeLYnk Controller, LSS100100, all versions prior to V1.5.0. The homeLYnk controller is susceptible to a cross-site scripting attack. User inputs can be manipulated to cause execution of JavaScript code.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.002
EPSS Ranking 43.6%
CVSS Severity
CVSS v3 Score 6.1
CVSS v2 Score 4.3
Products affected by CVE-2017-5157
-
cpe:2.3:h:schneider-electric:homelynk_controller_lss100100:-
-
cpe:2.3:o:schneider_electric:homelynk_controller_lss100100_firmware:1.3.0