PT-2025-44163 · Ipfire · Ipfire
Alex Williams
·
Published
2025-10-28
·
Updated
2025-10-28
·
CVE-2025-34304
CVSS v4.0
7.1
High
| Vector | AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
IPFire versions prior to 2.29 (Core Update 198)
Description
IPFire versions prior to 2.29 (Core Update 198) contain a SQL injection issue. An authenticated attacker can manipulate the SQL query when viewing OpenVPN connection logs through the
CONNECTION NAME parameter. The application sends an HTTP POST request to the ''/cgi-bin/logs.cgi/ovpnclients.dat'' Request-URI, inserting the value of the CONNECTION NAME parameter directly into the WHERE clause without proper sanitization. This can allow an attacker to disclose sensitive information from the database.Recommendations
Update to version 2.29 (Core Update 198) or later.
Fix
SQL injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Ipfire