Vulnerability Description
Smoothwall Express 3.1-SP4-polar-x86_64-update9 contains multiple stored cross-site scripting vulnerabilities in the preferences.cgi script that allow attackers to inject malicious scripts through the HOSTNAME, KEYMAP, and OPENNESS parameters. Attackers can submit POST requests with script payloads to preferences.cgi to store malicious code that executes in the browsers of users accessing the preferences page.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Smoothwall | Smoothwall Express | 3.1 |
Related Weaknesses (CWE)
References
- http://www.smoothwall.orgProduct
- https://www.exploit-db.com/exploits/46333ExploitThird Party AdvisoryVDB Entry
- https://www.vulncheck.com/advisories/smoothwall-express-preferencescgi-cross-sitBroken Link
FAQ
What is CVE-2019-25395?
CVE-2019-25395 is a vulnerability with a CVSS score of 7.2 (HIGH). Smoothwall Express 3.1-SP4-polar-x86_64-update9 contains multiple stored cross-site scripting vulnerabilities in the preferences.cgi script that allow attackers to inject malicious scripts through the...
How severe is CVE-2019-25395?
CVE-2019-25395 has been rated HIGH with a CVSS base score of 7.2/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2019-25395?
Check the references section above for vendor advisories and patch information. Affected products include: Smoothwall Smoothwall Express.