CVE-2023-24182: XSS
LuCI openwrt-22.03 branch git-22.361.69894-438c598 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the component /system/sshkeys.js.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2023-24182?
The severity of CVE-2023-24182 is medium with a CVSS score of 5.4.
What is the description of CVE-2023-24182?
CVE-2023-24182 is a stored cross-site scripting (XSS) vulnerability in LuCI openwrt-22.03 branch git-22.361.69894-438c598 via the /system/sshkeys.js component.
How does CVE-2023-24182 affect the software?
CVE-2023-24182 affects OpenWrt version 22.03.3 running LuCI openwrt-22.03 branch git-22.361.69894-438c598.
Is there a fix for CVE-2023-24182?
Yes, there have been commits made to the OpenWrt LuCI repository to address the vulnerability. Updating to the latest version of LuCI should fix the issue.
Where can I find more information about CVE-2023-24182?
you can find more information about CVE-2023-24182 on the GitHub security advisory page (https://github.com/ABB-EL/external-vulnerability-disclosures/security/advisories/GHSA-7vqh-2r8q-rjg2) and the OpenWrt LuCI repository commits (https://github.com/openwrt/luci/commit/0186d7eae0e123a409e9919a83fdfecc7945c984, https://github.com/openwrt/luci/commit/588381e2111079265cc3b20af33507052f1b58cb).