← Zurück zur CVE-Suche

CVE-2026-67352

luci-app-https-dns-proxy

Beschreibung

luci-app-https-dns-proxy contains a stored cross-site scripting vulnerability in the resolver_url parameter that allows authenticated users to inject active HTML. When an administrator views the HTTPS DNS Proxy status page, the resolver URL is rendered as raw HTML and executes JavaScript in the administrator-s browser origin.

CVSS 7.6EPSS 0.214%Risiko 0.77
Quelle öffnen
Veröffentlicht
2026-08-01 13:17:05
Betroffene Versionen
unknown
Typ
Webanwendung
Zuletzt geändert
2026-08-03 17:16:42
Vektor
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:L/A:N