PT-2026-20499 · Ipfire · Ipfire
Ozer Goker
·
Published
2026-02-18
·
Updated
2026-02-18
·
CVE-2019-25397
CVSS v3.1
6.1
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
IPFire version 2.21 Core Update 127
Description
The software contains multiple reflected cross-site scripting issues in the
hosts.cgi script. Attackers can inject malicious scripts through unvalidated parameters. Specifically, attackers can send POST requests with script payloads in the KEY1, IP, HOST, or DOM parameters to execute arbitrary JavaScript in users' browsers.Recommendations
Apply updates to address the issue in the
hosts.cgi script.
Validate all input parameters before processing them in the hosts.cgi script.
Sanitize user-supplied data to prevent the injection of malicious scripts.
Restrict access to the hosts.cgi script to authorized users only.Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Ipfire