Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-g4hv-3pw6-5x66

Опубликовано: 16 фев. 2026
Источник: github
Github: Не прошло ревью
CVSS4: 5.3
CVSS3: 7.2

Описание

Smoothwall Express 3.1-SP4-polar-x86_64-update9 contains multiple stored cross-site scripting vulnerabilities in the preferences.cgi script that allow attackers to inject malicious scripts through the HOSTNAME, KEYMAP, and OPENNESS parameters. Attackers can submit POST requests with script payloads to preferences.cgi to store malicious code that executes in the browsers of users accessing the preferences page.

Smoothwall Express 3.1-SP4-polar-x86_64-update9 contains multiple stored cross-site scripting vulnerabilities in the preferences.cgi script that allow attackers to inject malicious scripts through the HOSTNAME, KEYMAP, and OPENNESS parameters. Attackers can submit POST requests with script payloads to preferences.cgi to store malicious code that executes in the browsers of users accessing the preferences page.

EPSS

Процентиль: 13%
0.00042
Низкий

5.3 Medium

CVSS4

7.2 High

CVSS3

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 7.2
nvd
4 месяца назад

Smoothwall Express 3.1-SP4-polar-x86_64-update9 contains multiple stored cross-site scripting vulnerabilities in the preferences.cgi script that allow attackers to inject malicious scripts through the HOSTNAME, KEYMAP, and OPENNESS parameters. Attackers can submit POST requests with script payloads to preferences.cgi to store malicious code that executes in the browsers of users accessing the preferences page.

EPSS

Процентиль: 13%
0.00042
Низкий

5.3 Medium

CVSS4

7.2 High

CVSS3

Дефекты

CWE-79