Loytec LWEB-802 before 5.0.8 fails to neutralise the project and mspParams request parameters before reflecting them into the generated page (CWE-79, CWE-116). An unauthenticated remote attacker can execute arbitrary JavaScript in a victim’s browser via a crafted link and thereby perform actions with the victim’s privileges.