PT-2025-44160 · Ipfire · Ipfire

Alex Williams

·

Published

2025-10-28

·

Updated

2025-10-28

·

CVE-2025-34301

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions IPFire versions prior to 2.29 (Core Update 198)
Description IPFire is affected by a stored cross-site scripting (XSS) issue. An authenticated attacker can inject arbitrary JavaScript code into the COUNTRY CODE parameter when creating a location group. The application issues an HTTP POST request with the ACTION parameter set to savelocationgrp. The value of the COUNTRY CODE parameter is stored and rendered in the web interface without proper sanitization, enabling the execution of malicious scripts in the context of other users.
Recommendations Update to version 2.29 (Core Update 198) or later.

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2025-34301

Affected Products

Ipfire