Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2025-34304

Опубликовано: 28 окт. 2025
Источник: nvd
CVSS3: 6.5
EPSS Низкий

Описание

IPFire versions prior to 2.29 (Core Update 198) contain a SQL injection vulnerability that allows an authenticated attacker to manipulate the SQL query used when viewing OpenVPN connection logs via the CONNECTION_NAME parameter. When viewing a range of OpenVPN connection logs, the application issues an HTTP POST request to the Request-URI /cgi-bin/logs.cgi/ovpnclients.dat and inserts the value of the CONNECTION_NAME parameter directly into the WHERE clause without proper sanitization or parameterization. The unsanitized value can alter the executed query and be used to disclose sensitive information from the database.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:ipfire:ipfire:*:*:*:*:*:*:*:*
Версия до 2.29 (исключая)
cpe:2.3:a:ipfire:ipfire:2.29:core_update183:*:*:*:*:*:*
cpe:2.3:a:ipfire:ipfire:2.29:core_update184:*:*:*:*:*:*
cpe:2.3:a:ipfire:ipfire:2.29:core_update185:*:*:*:*:*:*
cpe:2.3:a:ipfire:ipfire:2.29:core_update186:*:*:*:*:*:*
cpe:2.3:a:ipfire:ipfire:2.29:core_update187:*:*:*:*:*:*
cpe:2.3:a:ipfire:ipfire:2.29:core_update188:*:*:*:*:*:*
cpe:2.3:a:ipfire:ipfire:2.29:core_update189:*:*:*:*:*:*
cpe:2.3:a:ipfire:ipfire:2.29:core_update190:*:*:*:*:*:*
cpe:2.3:a:ipfire:ipfire:2.29:core_update191:*:*:*:*:*:*
cpe:2.3:a:ipfire:ipfire:2.29:core_update192:*:*:*:*:*:*
cpe:2.3:a:ipfire:ipfire:2.29:core_update193:*:*:*:*:*:*
cpe:2.3:a:ipfire:ipfire:2.29:core_update194:*:*:*:*:*:*
cpe:2.3:a:ipfire:ipfire:2.29:core_update195:*:*:*:*:*:*
cpe:2.3:a:ipfire:ipfire:2.29:core_update196:*:*:*:*:*:*
cpe:2.3:a:ipfire:ipfire:2.29:core_update197:*:*:*:*:*:*

EPSS

Процентиль: 10%
0.00034
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-89

Связанные уязвимости

CVSS3: 6.5
github
3 месяца назад

IPFire versions prior to 2.29 (Core Update 198) contain a SQL injection vulnerability that allows an authenticated attacker to manipulate the SQL query used when viewing OpenVPN connection logs via the CONNECTION_NAME parameter. When viewing a range of OpenVPN connection logs, the application issues an HTTP POST request to the Request-URI /cgi-bin/logs.cgi/ovpnclients.dat and inserts the value of the CONNECTION_NAME parameter directly into the WHERE clause without proper sanitization or parameterization. The unsanitized value can alter the executed query and be used to disclose sensitive information from the database.

EPSS

Процентиль: 10%
0.00034
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-89