10-17-2024 07:02 PM
A recent security scan of our Lansweeper server detected a Cross-site Scripting Attack vulnerability. Checking Lansweeper knowledge base I found this in a security related document:
X-XSS-Protection: When set to 1, this setting enables the browser's XSS filter, providing an additional layer of defense against cross-site scripting attacks. This setting cannot be altered.
I made this change for LS site in IIS (I am not sure why it says his setting cannot be altered), but the scan still returns the same alert. Has anyone seen this before and if so, have you been able to resolve the issue?
Solved! Go to Solution.
10-20-2024 06:18 AM
We resolved the issue by only allowing HTTPS connections to the server.
10-20-2024 06:18 AM
We resolved the issue by only allowing HTTPS connections to the server.
10-28-2024 09:34 PM
I spoke too soon. The latest scan found the exact same issue on port 443. So, it is even detected when the site only answers to HTTPS calls.
10-17-2024 07:56 PM
Hi, can you confirm the LS and IIS version that you are using? Also, the tool that you ran to scan for vulnerabilities?.
Thks
10-17-2024 08:32 PM
IS 10.0.17763.1
LS 11.2.1.2
Scanning is done with Connectsecure
Experience Lansweeper with your own data. Sign up now for a 14-day free trial.
Try Now