CVE-2019-25392: Smoothwall Express 3.1 'iptools.cgi' Cross-Site Scripting
Smoothwall Express 3.1-SP4-polar-x8664-update9 contains a reflected cross-site scripting vulnerability that allows unauthenticated attackers to inject malicious scripts by manipulating the IP parameter. Attackers can send POST requests to the iptools.cgi endpoint with script payloads in the IP parameter to execute arbitrary JavaScript in victim browsers.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2019-25392?
CVE-2019-25392 has a high severity due to its ability to allow unauthenticated attackers to execute malicious scripts.
How do I fix CVE-2019-25392?
To fix CVE-2019-25392, update to the latest version of Smoothwall Express that addresses this vulnerability.
What type of vulnerability is CVE-2019-25392?
CVE-2019-25392 is a reflected cross-site scripting (XSS) vulnerability.
Who is affected by CVE-2019-25392?
Users of Smoothwall Express 3.1-SP4-polar-x86_64-update9 are affected by CVE-2019-25392.
What impact does CVE-2019-25392 have on users?
CVE-2019-25392 allows attackers to inject malicious scripts, potentially leading to data theft or session hijacking.