Stored Cross-Site Scripting in OpenWrt luci-app-https-dns-proxy
CVE-2026-67352
6.8MEDIUM
What is CVE-2026-67352?
The luci-app-https-dns-proxy contains a stored cross-site scripting vulnerability that affects how the resolver_url parameter is handled. This vulnerability allows authenticated users to inject malicious JavaScript into the status page viewed by administrators. When the administrator accesses the HTTPS DNS Proxy status page, the resolver URL is displayed as raw HTML, leading to the execution of arbitrary JavaScript within the browser. This exploitation can potentially compromise admin session integrity and enable further attacks, highlighting the need for timely security measures.
Affected Version(s)
luci 0
