IPFire 2.21 – Core Update 127 | Cross-Site Scripting
IPFire is a Linux distribution that focusses on easy setup, good handling and high level of security. It is operated via an intuitive web-based interface which offers many configuration options for beginning and experienced system administrators. IPFire is maintained by developers who are concerned about security and who update the product regularly to keep it secure. IPFire ships with a custom package manager called Pakfire and the system can be expanded with various add-ons. This vulnerability is a Cross-Site Scripting (XSS) vulnerability which allows an attacker to inject malicious JavaScript code into the web application. The vulnerability exists in five different parameters, four of which are reflected XSS and one is stored XSS.