CVE-2019-25386: medium-severity vulnerability in Smoothwall Express
Smoothwall Express 3.1 'dmzholes.cgi' Cross-Site Scripting
Published · Updated
13Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackcvss 5.1epss 0.2%
exploitation probability
0.2%top 86% of all CVEs
observed exploitation
nono source reports it
Smoothwall Express 3.1-SP4-polar-x86_64-update9 contains multiple reflected cross-site scripting vulnerabilities in the dmzholes.cgi script that allow attackers to inject malicious scripts through unvalidated parameters. Attackers can submit POST requests with script payloads in the SRC_IP, DEST_IP, or COMMENT parameters to execute arbitrary JavaScript in users' browsers.
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N
Affected products
Smoothwall · Smoothwall ExpressRelated CVEs — Smoothwall Express
In the same product, most dangerous first.
CVE-2011-1084—CVE-2011-1084EPSS 0.6%CVE-2011-1085—CVE-2011-1085EPSS 0.5%CVE-2019-25382MEDIUMSmoothwall Express 3.1 'time.cgi' Cross-Site ScriptingEPSS 0.3%CVE-2019-25379MEDIUMSmoothwall Express 3.1 'urlfilter.cgi' Cross-Site ScriptingEPSS 0.3%CVE-2019-25392MEDIUMSmoothwall Express 3.1 'iptools.cgi' Cross-Site ScriptingEPSS 0.3%CVE-2019-25389MEDIUMSmoothwall Express 3.1 'timedaccess.cgi' Cross-Site ScriptingEPSS 0.3%