Get a Pentest and security assessment of your IT network.

2021-current

CVE-2020-19204 – An authenticated Stored Cross-Site Scriptiong (XSS) vulnerability exists

An authenticated Stored Cross-Site Scriptiong (XSS) vulnerability exists in Lightning Wire Labs IPFire 2.21 (x86_64) – Core Update 130 in the “routing.cgi” Routing Table Entries via the “Remark” text box or “remark” parameter. It allows an authenticated WebGUI user to execute Stored Cross-site Scripting in the Routing Table Entries.

 

Source: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-19204

Reference (s):

  • https://blog.ipfire.org/post/ipfire-2-23-core-update-133-has-been-released
  • https://gist.github.com/dharmeshbaskaran/1fdc069c0ad729d12bf3304b5f19b02d
  • https://www.lightningwirelabs.com
Related posts
2021-current

CVE-2004-1715 - Directory traversal vulnerability in MIMEsweeper for Web before 5.0.4 all

2021-current

CVE-2014-9235 - Multiple SQL injection vulnerabilities in Zoph (aka Zoph Organizes Photos

2021-current

CVE-2020-0828 - A remote code execution vulnerability exists in the way that the ChakraCo

2021-current

CVE-2020-14827 - Vulnerability in the MySQL Server product of Oracle MySQL (component: Ser