PT-2023-23005 · Unknown · X-Wrt Luci
40826D
·
Published
2023-06-03
·
Updated
2024-05-17
·
CVE-2023-3085
CVSS v3.1
6.1
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
X-WRT luci versions up to 22.10 b202303061504
Description
A problematic issue has been found in the 404 Error Template Handler component, affecting the function
run action of the file modules/luci-base/ucode/dispatcher.uc. The manipulation of the argument request path leads to cross-site scripting. The attack may be initiated remotely.Recommendations
To address this issue, upgrade to version 22.10 b202303121313. As a temporary workaround, consider restricting access to the
run action function of the dispatcher.uc file until the patch is applied. Additionally, avoid manipulating the request path argument in the affected component to minimize the risk of exploitation.Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
X-Wrt Luci