NONE · 0

CVE-2025-1239

A stored cross-site scripting (XSS) vulnerability exists in the management interface of WatchGuard Firebox appliances via the Blocked Sites list. An authenticated remote attacker with administrator pr...

Vulnerability Description

A stored cross-site scripting (XSS) vulnerability exists in the management interface of WatchGuard Firebox appliances via the Blocked Sites list. An authenticated remote attacker with administrator privileges could exploit this vulnerability to execute arbitrary JavaScript code in the Firebox management interface of another management user.

Related Weaknesses (CWE)

References

FAQ

What is CVE-2025-1239?

CVE-2025-1239 is a documented vulnerability. A stored cross-site scripting (XSS) vulnerability exists in the management interface of WatchGuard Firebox appliances via the Blocked Sites list. An authenticated remote attacker with administrator pr...

How severe is CVE-2025-1239?

CVSS scoring is not yet available for CVE-2025-1239. Check NVD for updates.

Is there a patch for CVE-2025-1239?

Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.