An authenticated Stored Cross-Site Scriptiong (XSS) vulnerability exists in Lightning Wire Labs IPFire 2.21 (x86_64) - Core Update 130 in the "routing.cgi" Routing Table Entries via the "Remark" text box or "remark" parameter. It allows an authenticated WebGUI user to execute Stored Cross-site Scripting in the Routing Table Entries.
References
Link | Resource |
---|---|
https://blog.ipfire.org/post/ipfire-2-23-core-update-133-has-been-released | Release Notes Vendor Advisory |
https://gist.github.com/dharmeshbaskaran/1fdc069c0ad729d12bf3304b5f19b02d | Mitigation Patch Third Party Advisory |
https://www.lightningwirelabs.com | Third Party Advisory |
History
No history.
MITRE Information
Status: PUBLISHED
Assigner: mitre
Published: 2021-07-12T15:22:38
Updated: 2021-07-20T17:08:16
Reserved: 2020-08-13T00:00:00
Link: CVE-2020-19204
JSON object: View
NVD Information
Status : Analyzed
Published: 2021-07-12T16:15:08.453
Modified: 2022-04-29T17:15:33.680
Link: CVE-2020-19204
JSON object: View
Redhat Information
No data.
CWE