5.4
CVE-2026-26352
- EPSS 0.14%
- Veröffentlicht 30.03.2026 16:49:16
- Zuletzt bearbeitet 14.04.2026 16:34:30
- Erkennungen
Smoothwall Express < 3.1 Update 13 Stored XSS in vpnmain.cgi via VPN_IP Parameter
Smoothwall Express versions prior to 3.1 Update 13 contain a stored cross-site scripting vulnerability in the /cgi-bin/vpnmain.cgi script due to improper sanitation of the VPN_IP parameter. Authenticated attackers can inject arbitrary JavaScript through VPN configuration settings that executes when the affected page is viewed by other users.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Smoothwall ≫ Smoothwall Express Version <= 3.0
Smoothwall ≫ Smoothwall Express Version 3.1 Update update1 SwEdition -
Smoothwall ≫ Smoothwall Express Version 3.1 Update update10 SwEdition -
Smoothwall ≫ Smoothwall Express Version 3.1 Update update11 SwEdition -
Smoothwall ≫ Smoothwall Express Version 3.1 Update update12 SwEdition -
Smoothwall ≫ Smoothwall Express Version 3.1 Update update2 SwEdition -
Smoothwall ≫ Smoothwall Express Version 3.1 Update update3 SwEdition -
Smoothwall ≫ Smoothwall Express Version 3.1 Update update4 SwEdition -
Smoothwall ≫ Smoothwall Express Version 3.1 Update update5 SwEdition -
Smoothwall ≫ Smoothwall Express Version 3.1 Update update6 SwEdition -
Smoothwall ≫ Smoothwall Express Version 3.1 Update update7 SwEdition -
Smoothwall ≫ Smoothwall Express Version 3.1 Update update8 SwEdition -
Smoothwall ≫ Smoothwall Express Version 3.1 Update update9 SwEdition -
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.14% | 0.035 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| disclosure@vulncheck.com | 5.4 | 2.3 | 2.7 |
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
|
| disclosure@vulncheck.com | 5.1 | 0 | 0 |
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
|
CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
https://community.smoothwall.org/forum/viewtopic.php?t=45095
https://www.vulncheck.com/advisories/smoothwall-express-stored-xss-in-vpnmain-cgi-via-vpn-ip-parameter