CyberRota Analysis
AI-GeneratedLuci-app-adblock-fast versions prior to 1.2.4-4 are vulnerable to a stored cross-site scripting (XSS) attack through the blocklist name field, allowing lower-privileged users to inject malicious HTML. This vulnerability can result in the execution of the injected payload in the administrator's browser when accessing the AdBlock Fast status page, potentially compromising sensitive information or session tokens. Administrators of systems using this application should prioritize updating to the latest version to mitigate the risk.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
luci-app-adblock-fast before 1.2.4-4 contains a stored cross-site scripting vulnerability in the blocklist name field that allows lower-privileged users to inject active HTML. When an administrator views the AdBlock Fast status page, the injected payload executes in the administrator's browser under the LuCI origin.