CVE-2019-25389: Smoothwall Express 3.1 'timedaccess.cgi' Cross-Site Scripting
Smoothwall Express 3.1-SP4-polar-x8664-update9 contains a reflected cross-site scripting vulnerability that allows unauthenticated attackers to inject malicious scripts by manipulating the MACHINES parameter. Attackers can craft requests to the timedaccess.cgi endpoint with script payloads in the MACHINES parameter to execute arbitrary JavaScript in users' browsers.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2019-25389?
CVE-2019-25389 has been classified as a medium severity vulnerability due to its potential to allow cross-site scripting attacks.
How do I fix CVE-2019-25389?
To fix CVE-2019-25389, you should update Smoothwall Express to the latest version that addresses this vulnerability.
Who is affected by CVE-2019-25389?
CVE-2019-25389 affects users of Smoothwall Express 3.1, specifically those running version 3.1-SP4-polar-x86_64-update9.
What type of attack can be executed through CVE-2019-25389?
An attacker can execute reflected cross-site scripting attacks through CVE-2019-25389 by manipulating the MACHINES parameter.
Can CVE-2019-25389 be exploited remotely?
Yes, CVE-2019-25389 can be exploited remotely as it allows unauthenticated attackers to inject malicious scripts.