PT-2023-23005 · Unknown · X-Wrt Luci
40826D
·
Publicado
2023-06-03
·
Atualizado
2024-05-17
·
CVE-2023-3085
CVSS v3.1
6.1
Média
| Vetor | AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
X-WRT luci versions up to 22.10 b202303061504
Description
A problematic issue has been found in the 404 Error Template Handler component, affecting the function
run action of the file modules/luci-base/ucode/dispatcher.uc. The manipulation of the argument request path leads to cross-site scripting. The attack may be initiated remotely.Recommendations
To address this issue, upgrade to version 22.10 b202303121313. As a temporary workaround, consider restricting access to the
run action function of the dispatcher.uc file until the patch is applied. Additionally, avoid manipulating the request path argument in the affected component to minimize the risk of exploitation.Correção
XSS
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
X-Wrt Luci