LuCI in OpenWrt 18.06.0 through 18.06.4 allows stored XSS via a crafted SSID.
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
Link | Tags |
---|---|
https://github.com/openwrt/luci/commit/bc17ef673f734ea8e7e696ba5735588da9111dcd | third party advisory patch |
https://openwrt.org/advisory/2019-11-05-1 | patch vendor advisory exploit |