vendor:
Smoothwall Express
by:
Ozer Goker
8.8
CVSS
HIGH
Cross-Site Scripting
79
CWE
Product Name: Smoothwall Express
Affected Version From: 3.1-SP4-polar-x86_64-update9
Affected Version To: 3.1-SP4-polar-x86_64-update9
Patch Exists: NO
Related CWE: N/A
CPE: o:smoothwall:smoothwall_express:3.1-sp4-polar-x86_64-update9
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: GNU/Linux
2019
Smoothwall Express 3.1-SP4-polar-x86_64-update9 | Cross-Site Scripting
Smoothwall Open Source Project was set up in 2000 to develop and maintain Smoothwall Express - a Free firewall that includes its own security-hardened GNU/Linux operating system and an easy-to-use web interface. The vulnerability is a Cross-Site Scripting (XSS) vulnerability which can be exploited by sending malicious payloads to the vulnerable parameters. The payloads are stored in the database and can be triggered when the vulnerable parameters are accessed. The vulnerability can be exploited by sending malicious payloads to the vulnerable parameters. The payloads are stored in the database and can be triggered when the vulnerable parameters are accessed.
Mitigation:
The best way to mitigate XSS attacks is to use a web application firewall (WAF) to filter out malicious requests. Additionally, developers should ensure that all user-supplied input is properly sanitized and validated before being used in the application.