CVE-2019-25385: Smoothwall Express 3.1 'outgoing.cgi' Cross-Site Scripting
Smoothwall Express 3.1-SP4-polar-x8664-update9 contains a reflected cross-site scripting vulnerability that allows attackers to inject malicious scripts by manipulating the MACHINE and MACHINECOMMENT parameters. Attackers can send POST requests to the outgoing.cgi endpoint with script payloads to execute arbitrary JavaScript in users' browsers and steal session data.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2019-25385?
CVE-2019-25385 is considered a moderate severity vulnerability due to its potential impact on user data and session integrity.
How do I fix CVE-2019-25385?
To fix CVE-2019-25385, upgrade Smoothwall Express to the latest version where the XSS vulnerability has been patched.
Who is affected by CVE-2019-25385?
CVE-2019-25385 affects users running Smoothwall Express 3.1-SP4-polar-x86_64-update9.
What type of vulnerability is CVE-2019-25385?
CVE-2019-25385 is classified as a Cross-Site Scripting (XSS) vulnerability.
What can attackers do with CVE-2019-25385?
Attackers can exploit CVE-2019-25385 to inject malicious scripts into web pages viewed by users, leading to possible data theft or session hijacking.