Vulnerability Description
Smoothwall Express 3.1-SP4-polar-x86_64-update9 contains a reflected cross-site scripting vulnerability that allows attackers to inject malicious scripts by manipulating the MACHINE and MACHINECOMMENT parameters. Attackers can send POST requests to the outgoing.cgi endpoint with script payloads to execute arbitrary JavaScript in users' browsers and steal session data.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Smoothwall | Smoothwall Express | 3.1 |
Related Weaknesses (CWE)
References
- http://www.smoothwall.orgProduct
- https://www.exploit-db.com/exploits/46333ExploitThird Party AdvisoryVDB Entry
- https://www.vulncheck.com/advisories/smoothwall-express-outgoingcgi-cross-site-sBroken Link
FAQ
What is CVE-2019-25385?
CVE-2019-25385 is a vulnerability with a CVSS score of 6.1 (MEDIUM). Smoothwall Express 3.1-SP4-polar-x86_64-update9 contains a reflected cross-site scripting vulnerability that allows attackers to inject malicious scripts by manipulating the MACHINE and MACHINECOMMENT...
How severe is CVE-2019-25385?
CVE-2019-25385 has been rated MEDIUM with a CVSS base score of 6.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2019-25385?
Check the references section above for vendor advisories and patch information. Affected products include: Smoothwall Smoothwall Express.