Loading HuntDB...

GHSA-28cg-8hgj-ww5p

GitHub Security Advisory

⚠ Unreviewed MODERATE Has CVE

Advisory Details

A stored cross-site scripting (XSS) issue was discovered within the Custom User Icons functionality of ASUS RT-AX88U running firmware versions 3.0.0.4.388.23110 and prior.  After a remote attacker logging in device with regular user privilege, the remote attacker can perform a Stored Cross-site Scripting (XSS) attack by uploading image which containing JavaScript code.

Related CVEs

Key Information

GHSA ID
GHSA-28cg-8hgj-ww5p
Published
July 31, 2023 6:30 AM
Last Modified
April 4, 2024 6:26 AM
CVSS Score
5.0 /10
Primary Ecosystem
Unknown
Primary Package
Unknown
GitHub Reviewed
✗ No

Dataset

Last updated: September 29, 2025 6:31 AM

Data from GitHub Advisory Database. This information is provided for research and educational purposes.