First published: Thu Nov 03 2022(Updated: )
OpenWRT LuCI version git-22.140.66206-02913be was discovered to contain a stored cross-site scripting (XSS) vulnerability in the component /system/sshkeys.js. This vulnerability allows attackers to execute arbitrary web scripts or HTML via crafted public key comments.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
OpenWRT LuCI | =git-22.140.66206-02913be |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this OpenWRT LuCI vulnerability is CVE-2022-41435.
The severity of CVE-2022-41435 is medium (5.4).
The component /system/sshkeys.js is affected by CVE-2022-41435.
CVE-2022-41435 allows attackers to execute arbitrary web scripts or HTML via crafted public key comments.
To fix the vulnerability in OpenWRT LuCI git-22.140.66206-02913be, update to a version that includes the fix, such as the commit 944b55738e7f9685865d5298248b7fbd7380749e.