First published: Thu Jan 21 2021(Updated: )
LuCI in OpenWrt 18.06.0 through 18.06.4 allows stored XSS via a crafted SSID.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
OpenWrt OpenWrt | >=18.06.0<=18.06.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2019-25015.
The title of the vulnerability is 'LuCI in OpenWrt 18.06.0 through 18.06.4 allows stored XSS via a crafted SSID.'
The severity of CVE-2019-25015 is medium with a CVSS score of 5.4.
The vulnerability affects OpenWrt versions 18.06.0 through 18.06.4.
The vulnerability can be exploited through a crafted SSID that allows for stored cross-site scripting (XSS) attacks.
Yes, a fix is available. It is recommended to update to a version of OpenWrt that is not affected by this vulnerability.
You can find more information about this vulnerability in the references provided: [GitHub](https://github.com/openwrt/luci/commit/bc17ef673f734ea8e7e696ba5735588da9111dcd) and [OpenWrt Advisory](https://openwrt.org/advisory/2019-11-05-1).