Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
LuCI DHCPv6 Lease Hostname Stored Cross-Site Scripting
Vulnerability Description
LuCI versions fail to properly encode DHCPv6 lease hostnames before rendering in status tables, allowing adjacent network attackers to inject HTML markup. Attackers can send a DHCPv6 Client FQDN containing script tags that execute in the administrator's browser when viewing DHCP lease pages.
CVSS Information
CVSS:3.1/AV:A/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
Vulnerability Type
在Web页面生成时对输入的转义处理不恰当(跨站脚本)
Vulnerability Title
OpenWRT luci 跨站脚本漏洞
Vulnerability Description
OpenWRT luci是OpenWRT社区开源的一款路由器配置界面。 OpenWRT luci存在跨站脚本漏洞,该漏洞源于在状态表中呈现DHCPv6租约主机名前未能正确编码,导致相邻网络攻击者注入HTML标记。攻击者可以通过发送包含脚本标签的DHCPv6 Client FQDN,在管理员查看DHCP租约页面时执行脚本。
CVSS Information
N/A
Vulnerability Type
N/A