IPFire < 2.19 Core Update 101 proxy.cgi RCE
36Vexday Risk Score
Patch soon. It has a working public exploit.
ssvc Attendcvss 8.7epss 1.2%
from disclosure to weapon0 days
Published on NVDJul 15
metasploitMay 4
exploitation probability
1.2%top 35% of all CVEs
observed exploitation
nono source reports it
A remote command execution vulnerability exists in IPFire before version 2.19 Core Update 101 via the 'proxy.cgi' CGI interface. An authenticated attacker can inject arbitrary shell commands through crafted values in the NCSA user creation form fields, leading to command execution with web server privileges.
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Affected products
IPFire Project · IPFireReferences
https://bugzilla.ipfire.org/show_bug.cgi?id=11087https://raw.githubusercontent.com/rapid7/metasploit-framework/master/modules/exploits/linux/http/ipfire_proxy_exec.rbhttps://www.asafety.fr/en/vuln-exploit-poc/xss-rce-ipfire-2-19-core-update-101-remote-command-execution/https://www.exploit-db.com/exploits/39765https://www.ipfire.org/news/ipfire-2-19-core-update-101-releasedhttps://www.vulncheck.com/advisories/ipfire-authenticated-rce