Security Advisory

CVE-2013-7033

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2014-05-19 14:00:00
Last updated 2024-08-06 17:53:45
Assigner mitre
CVSS score not scored
State PUBLISHED

Description

LiveZilla before 5.1.2.1 includes the operator password in plaintext in Javascript code that is generated by lz/mobile/chat.php, which might allow remote attackers to obtain sensitive information and gain privileges by accessing the loginName and loginPassword variables using an independent cross-site scripting (XSS) attack.