PT-2021-10597 · Ipfire · Ipfire
Published
2021-06-28
·
Updated
2021-07-01
·
CVE-2020-21142
CVSS v3.1
6.1
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions:
IPFire version 2.23
Description:
The issue is related to a Cross Site Scripting (XSS) vulnerability. It affects the IPFire web UI, specifically in the mail.cgi component. This vulnerability can be exploited via the IPfire web UI.
Recommendations:
For IPFire version 2.23, update to a version that includes a fix for this issue, as the current version is affected by the Cross Site Scripting (XSS) vulnerability in the mail.cgi component of the IPfire web UI. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Ipfire