CVE-2022-41435: XSS
Published Nov 3, 2022
·Updated
OpenWRT LuCI version git-22.140.66206-02913be was discovered to contain a stored cross-site scripting (XSS) vulnerability in the component /system/sshkeys.js. This vulnerability allows attackers to execute arbitrary web scripts or HTML via crafted public key comments.
Affected Software
1 affected component
OpenWrt LuCI=git-22.140.66206-02913be
Event History
Nov 3, 2022
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·12:15 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the vulnerability ID for this OpenWRT LuCI vulnerability?
The vulnerability ID for this OpenWRT LuCI vulnerability is CVE-2022-41435.
2
What is the severity of CVE-2022-41435?
The severity of CVE-2022-41435 is medium (5.4).
3
Which component of OpenWRT LuCI is affected by CVE-2022-41435?
The component /system/sshkeys.js is affected by CVE-2022-41435.
4
What is the impact of CVE-2022-41435?
CVE-2022-41435 allows attackers to execute arbitrary web scripts or HTML via crafted public key comments.
5
How can I fix the vulnerability in OpenWRT LuCI git-22.140.66206-02913be?
To fix the vulnerability in OpenWRT LuCI git-22.140.66206-02913be, update to a version that includes the fix, such as the commit 944b55738e7f9685865d5298248b7fbd7380749e.