CVE-2019-25015: XSS
LuCI in OpenWrt 18.06.0 through 18.06.4 allows stored XSS via a crafted SSID.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the vulnerability ID?
The vulnerability ID is CVE-2019-25015.
What is the title of the vulnerability?
The title of the vulnerability is 'LuCI in OpenWrt 18.06.0 through 18.06.4 allows stored XSS via a crafted SSID.'
What is the severity of CVE-2019-25015?
The severity of CVE-2019-25015 is medium with a CVSS score of 5.4.
How does the vulnerability affect OpenWrt?
The vulnerability affects OpenWrt versions 18.06.0 through 18.06.4.
How can the vulnerability be exploited?
The vulnerability can be exploited through a crafted SSID that allows for stored cross-site scripting (XSS) attacks.
Is there a fix available for CVE-2019-25015?
Yes, a fix is available. It is recommended to update to a version of OpenWrt that is not affected by this vulnerability.
Where can I find more information about this vulnerability?
You can find more information about this vulnerability in the references provided: [GitHub](https://github.com/openwrt/luci/commit/bc17ef673f734ea8e7e696ba5735588da9111dcd) and [OpenWrt Advisory](https://openwrt.org/advisory/2019-11-05-1).