5.4

CVE-2026-26352

Smoothwall Express < 3.1 Update 13 Stored XSS in vpnmain.cgi via VPN_IP Parameter

Smoothwall Express versions prior to 3.1 Update 13 contain a stored cross-site scripting vulnerability in the /cgi-bin/vpnmain.cgi script due to improper sanitation of the VPN_IP parameter. Authenticated attackers can inject arbitrary JavaScript through VPN configuration settings that executes when the affected page is viewed by other users.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
SmoothwallSmoothwall Express Version <= 3.0
SmoothwallSmoothwall Express Version3.1 Updateupdate1 SwEdition-
SmoothwallSmoothwall Express Version3.1 Updateupdate10 SwEdition-
SmoothwallSmoothwall Express Version3.1 Updateupdate11 SwEdition-
SmoothwallSmoothwall Express Version3.1 Updateupdate12 SwEdition-
SmoothwallSmoothwall Express Version3.1 Updateupdate2 SwEdition-
SmoothwallSmoothwall Express Version3.1 Updateupdate3 SwEdition-
SmoothwallSmoothwall Express Version3.1 Updateupdate4 SwEdition-
SmoothwallSmoothwall Express Version3.1 Updateupdate5 SwEdition-
SmoothwallSmoothwall Express Version3.1 Updateupdate6 SwEdition-
SmoothwallSmoothwall Express Version3.1 Updateupdate7 SwEdition-
SmoothwallSmoothwall Express Version3.1 Updateupdate8 SwEdition-
SmoothwallSmoothwall Express Version3.1 Updateupdate9 SwEdition-
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.03% 0.098
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
disclosure@vulncheck.com 5.4 2.3 2.7
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
disclosure@vulncheck.com 5.1 0 0
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.