PT-2025-44168 · Ipfire · Ipfire
Alex Williams
·
Published
2025-10-28
·
Updated
2025-10-29
·
CVE-2025-34309
CVSS v3.1
5.4
Medium
| Vector | AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
IPFire versions prior to 2.29 (Core Update 198)
Description
The software contains a stored cross-site scripting (XSS) issue that allows an authenticated attacker to inject arbitrary JavaScript code. This is achieved by manipulating the
SERVICE, LOGIN, and PASSWORD parameters when creating or editing a Dynamic DNS host. The application sends an HTTP POST request to the /cgi-bin/ddns.cgi endpoint, saving the values of these parameters. These values are then displayed without proper sanitation or encoding, enabling script execution in the context of other users viewing or editing the Dynamic DNS entries.Recommendations
Update to version 2.29 (Core Update 198) or later.
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Ipfire