PT-2026-8370 · Smoothwall · Smoothwall Express

Ozer Goker

·

Published

2026-02-16

·

Updated

2026-02-20

·

CVE-2019-25387

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Smoothwall Express version 3.1-SP4-polar-x86 64-update9
Description The software contains a reflected cross-site scripting issue that allows unauthenticated attackers to inject malicious scripts. Attackers can submit crafted input to the /xtaccess.cgi endpoint to achieve this. Specifically, script payloads can be injected through the EXT, DEST PORT, or COMMENT parameters via POST requests, leading to the execution of arbitrary JavaScript in victim browsers.
Recommendations Apply input validation and output encoding to the EXT, DEST PORT, and COMMENT parameters in the /xtaccess.cgi endpoint.

Exploit

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2019-25387

Affected Products

Smoothwall Express