openwrt / luci

LuCI - OpenWrt Configuration Interface
Apache License 2.0
6.38k stars 2.53k forks source link

Reporting security bugs on openwrt-19.07 #3757

Closed alisaeed closed 4 years ago

alisaeed commented 4 years ago

Hello, hope you are doing well,

We performed a security scan using acunetix and the results show some security issues. Please see the attachment. branch: openwrt-19.07 Vulnerability tool: Acunetix.Web.12.0.181218140.Retail

Best Regards.

report.pdf

alisaeed commented 4 years ago

Thanks a lot @jow- But yet, there are a few bugs, after your vulnerabilities fixing. I attached a new report.

20200316_Developer_https_192_168_1_100_cgi_binluci.pdf

jow- commented 4 years ago

Did you validate the claimed CSRF protection issue with a reliable reproducer? I am not going to fix the low and informational issues.