Medium severity6.1NVD Advisory· Published Jan 22, 2020· Updated Jun 17, 2026
CVE-2018-17981
CVE-2018-17981
Description
Lifesize Express ls ex2_4.7.10 2000 (14) devices allow XSS via the interface/interface.php brand parameter.
Affected products
4- cpe:2.3:o:lifesize:express_220_firmware:ls_ex2_4.7.10_2000_\(14\):*:*:*:*:*:*:*
- cpe:2.3:o:lifesize:room_220i_firmware:ls_rm2_4.11.8_\(14\):*:*:*:*:*:*:*
- Lifesize/Expressdescription
Patches
Vulnerability mechanics
References
1- sku11army.blogspot.com/2020/01/lifesize-devices-allow-xss-via.htmlnvdExploitThird Party Advisory
News mentions
0No linked articles in our index yet.