Description
SmartHouse Webapp 6.5.33 contains multiple cross-site request forgery and cross-site scripting vulnerabilities that allow attackers to perform unauthorized actions. Attackers can exploit these vulnerabilities by tricking logged-in users into visiting malicious websites or injecting malicious scripts into various application parameters.
Problem types
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Cross-Site Request Forgery (CSRF)
Product status
Credits
LiquidWorm as Gjoko Krstic of Zero Science Lab
References
www.zeroscience.mk/en/vulnerabilities/ZSL-2019-5543.php
www.exploit-db.com/exploits/47730 (ExploitDB-47730)
www.smarthouse.nu (SmartHouse Product Website)
www.zeroscience.mk/en/vulnerabilities/ZSL-2019-5543.php (Zero Science Lab Disclosure (ZSL-2019-5553))
Data based on CVE®. Copyright © 1999-2025, The MITRE Corporation. All rights reserved.