CVE-2023-24181: XSS
Published Apr 10, 2023
·Updated
LuCI openwrt-22.03 branch git-22.361.69894-438c598 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the component /openvpn/pageswitch.htm.
Affected Software
1 affected component
OpenWrt LuCI=22.03.3
Remediation
Event History
Apr 10, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·02:15 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the vulnerability ID for this LuCI vulnerability?
The vulnerability ID for this LuCI vulnerability is CVE-2023-24181.
2
What is the severity of CVE-2023-24181?
The severity of CVE-2023-24181 is medium, with a CVSS score of 5.4.
3
What is the affected software of CVE-2023-24181?
The affected software of CVE-2023-24181 is OpenWRT LuCI version 22.03.3.
4
What is the CWE ID associated with CVE-2023-24181?
The CWE ID associated with CVE-2023-24181 is CWE-79.
5
How can I fix the reflected cross-site scripting (XSS) vulnerability in LuCI?
To fix the reflected cross-site scripting (XSS) vulnerability in LuCI, update to the patched version specified in the references.