CVE-2019-25386: Smoothwall Express 3.1 'dmzholes.cgi' Cross-Site Scripting
Smoothwall Express 3.1-SP4-polar-x8664-update9 contains multiple reflected cross-site scripting vulnerabilities in the dmzholes.cgi script that allow attackers to inject malicious scripts through unvalidated parameters. Attackers can submit POST requests with script payloads in the SRCIP, DESTIP, or COMMENT parameters to execute arbitrary JavaScript in users' browsers.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2019-25386?
CVE-2019-25386 is considered a medium severity vulnerability due to the potential for cross-site scripting attacks.
How do I fix CVE-2019-25386?
To fix CVE-2019-25386, ensure you apply the latest updates for Smoothwall Express and validate all user inputs in the dmzholes.cgi script.
What software is affected by CVE-2019-25386?
CVE-2019-25386 affects Smoothwall Express 3.1, specifically the dmzholes.cgi script.
What type of attack is associated with CVE-2019-25386?
CVE-2019-25386 is associated with reflected cross-site scripting attacks that can allow attackers to inject malicious scripts.
Who can exploit CVE-2019-25386?
Any unauthenticated user can potentially exploit CVE-2019-25386 to execute cross-site scripting attacks on affected Smoothwall Express installations.