PT-2026-67336 · Openwrt · Luci-App-Adblock-Fast
CVSS v3.1
5.4
Medium
| Vector | AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
luci-app-adblock-fast versions prior to 1.2.4-4
Description
A stored cross-site scripting issue exists in the blocklist name field, specifically involving the
file url.name variable. This allows users with lower privileges to inject active HTML. The injected payload executes within the administrator's browser under the LuCI origin when the administrator accesses the AdBlock Fast status page.Recommendations
Update luci-app-adblock-fast to version 1.2.4-4 or later.
Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Luci-App-Adblock-Fast