PT-2026-29062 · Smoothwall · Express
Alex Williams
+1
·
Published
2026-03-30
·
Updated
2026-03-30
·
CVE-2026-27508
CVSS v3.1
5.4
Medium
| AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N |
Smoothwall Express versions prior to 3.1 Update 13 contain a reflected cross-site scripting vulnerability in the /redirect.cgi endpoint due to improper sanitation of the url parameter. Attackers can craft malicious URLs with javascript: schemes that execute arbitrary JavaScript in victims' browsers when clicked through the unsanitized link.
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Express