CVE-2019-18993: XSS
Published Dec 3, 2019
·Updated
OpenWrt 18.06.4 allows XSS via the "New port forward" Name field to the cgi-bin/luci/admin/network/firewall/forwards URI (this can occur, for example, on a TP-Link Archer C7 device).
Affected Software
1 affected component
OpenWrt OpenWrt=18.06.4
Remediation
Event History
Dec 3, 2019
CVE Published
via MITRE·07:29 PM
Data Sourced
via MITRE·07:29 PM
Description
Frequently Asked Questions
1
What is the vulnerability ID for this OpenWrt vulnerability?
The vulnerability ID for this OpenWrt vulnerability is CVE-2019-18993.
2
What is the severity of CVE-2019-18993?
The severity of CVE-2019-18993 is medium with a severity value of 5.4.
3
How does CVE-2019-18993 affect OpenWrt 18.06.4?
CVE-2019-18993 allows XSS (Cross-Site Scripting) attacks via the "New port forward" Name field on OpenWrt 18.06.4.
4
How can an XSS attack be performed through CVE-2019-18993?
An XSS attack can be performed by injecting malicious scripts into the "New port forward" Name field on OpenWrt 18.06.4.
5
Is there a fix available for CVE-2019-18993?
Yes, there is a fix available for CVE-2019-18993. It is recommended to update to a version that includes the fix.