luci-app-adblock-fast before 1.2.4-4 contains a stored cross-site scripting vulnerability in the blocklist name field that allows lower-privileged users to inject active HTML. When an administrator views the AdBlock Fast status page, the injected payload executes in the administrator's browser under the LuCI origin.
References
Configurations
No configuration.
History
03 Aug 2026, 17:16
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://github.com/openwrt/luci/security/advisories/GHSA-q335-4c83-c88h - |
02 Aug 2026, 13:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-08-02 13:16
Updated : 2026-08-03 17:16
NVD link : CVE-2026-68583
Mitre link : CVE-2026-68583
CVE.ORG link : CVE-2026-68583
JSON object : View
Products Affected
No product.
CWE
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
