PT-2025-34800 · Ipfire · Ipfire

·

CVE-2025-50976

·

Published

2025-08-26

·

Updated

2025-08-26

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions: IPFire version 2.29
Description: The DNS management interface (dns.cgi) in IPFire fails to properly sanitize user-supplied input in the NAMESERVER, REMARK, and TLS HOSTNAME query parameters. This results in a reflected cross-site scripting (XSS) issue.
Recommendations: Ensure proper input validation and sanitization are implemented for the NAMESERVER, REMARK, and TLS HOSTNAME query parameters in the dns.cgi interface.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-50976

Affected Products

Ipfire