VYPR
High severity7.5NVD Advisory· Published Apr 18, 2018· Updated Jun 17, 2026

CVE-2018-10193

CVE-2018-10193

Description

LogMeIn LastPass through 4.15.0 allows remote attackers to cause a denial of service (browser hang) via an HTML document because the resource consumption of onloadwff.js grows with the number of INPUT elements.

Affected products

2
  • Logmein/LastPass2 versions
    cpe:2.3:a:logmein:lastpass:*:*:*:*:*:chrome:*:*+ 1 more
    • cpe:2.3:a:logmein:lastpass:*:*:*:*:*:chrome:*:*range: <=4.15.0
    • (no CPE)range: <=4.15.0

Patches

Vulnerability mechanics

References

3

News mentions

0

No linked articles in our index yet.