5.4
CVE-2026-26352
- EPSS 0.03%
- Veröffentlicht 30.03.2026 16:49:16
- Zuletzt bearbeitet 14.04.2026 16:34:30
- Quelle disclosure@vulncheck.com
- CVE-Watchlists
- Unerledigt
Smoothwall Express < 3.1 Update 13 Stored XSS in vpnmain.cgi via VPN_IP Parameter
Smoothwall Express versions prior to 3.1 Update 13 contain a stored cross-site scripting vulnerability in the /cgi-bin/vpnmain.cgi script due to improper sanitation of the VPN_IP parameter. Authenticated attackers can inject arbitrary JavaScript through VPN configuration settings that executes when the affected page is viewed by other users.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Smoothwall ≫ Smoothwall Express Version <= 3.0
Smoothwall ≫ Smoothwall Express Version3.1 Updateupdate1 SwEdition-
Smoothwall ≫ Smoothwall Express Version3.1 Updateupdate10 SwEdition-
Smoothwall ≫ Smoothwall Express Version3.1 Updateupdate11 SwEdition-
Smoothwall ≫ Smoothwall Express Version3.1 Updateupdate12 SwEdition-
Smoothwall ≫ Smoothwall Express Version3.1 Updateupdate2 SwEdition-
Smoothwall ≫ Smoothwall Express Version3.1 Updateupdate3 SwEdition-
Smoothwall ≫ Smoothwall Express Version3.1 Updateupdate4 SwEdition-
Smoothwall ≫ Smoothwall Express Version3.1 Updateupdate5 SwEdition-
Smoothwall ≫ Smoothwall Express Version3.1 Updateupdate6 SwEdition-
Smoothwall ≫ Smoothwall Express Version3.1 Updateupdate7 SwEdition-
Smoothwall ≫ Smoothwall Express Version3.1 Updateupdate8 SwEdition-
Smoothwall ≫ Smoothwall Express Version3.1 Updateupdate9 SwEdition-
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.03% | 0.098 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| disclosure@vulncheck.com | 5.4 | 2.3 | 2.7 |
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
|
| disclosure@vulncheck.com | 5.1 | 0 | 0 |
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
|
CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.