PT-2025-34800 · Ipfire · Ipfire
4Rdr
·
Published
2025-08-26
·
Updated
2025-08-26
·
CVE-2025-50976
CVSS v3.1
6.1
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions:
IPFire version 2.29
Description:
The DNS management interface (dns.cgi) in IPFire fails to properly sanitize user-supplied input in the
NAMESERVER, REMARK, and TLS HOSTNAME query parameters. This results in a reflected cross-site scripting (XSS) issue.Recommendations:
Ensure proper input validation and sanitization are implemented for the
NAMESERVER, REMARK, and TLS HOSTNAME query parameters in the dns.cgi interface.Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Ipfire