Description
cgi_handle_request in uhttpd in OpenWrt through 18.06.1 and LEDE through 17.01 has unauthenticated reflected XSS via the URI, as demonstrated by a cgi-bin/?[XSS] URI.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2018-11315 | cgi_handle_request in uhttpd in OpenWrt through 18.06.1 and LEDE through 17.01 has unauthenticated reflected XSS via the URI, as demonstrated by a cgi-bin/?[XSS] URI. |
References
| Link | Providers |
|---|---|
| https://bugs.openwrt.org/index.php?do=details&task_id=1974 |
|
History
No history.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-05T11:44:19.424Z
Reserved: 2018-11-28T00:00:00.000Z
Link: CVE-2018-19630
No data.
Status : Modified
Published: 2018-11-28T10:29:00.190
Modified: 2024-11-21T03:58:19.273
Link: CVE-2018-19630
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD