Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
An authenticated Stored XSS (Cross-site Scripting) exists in the "captive.cgi" Captive Portal via the "Title of Login Page" text box or "TITLE" parameter in IPFire 2.21 (x86_64) - Core Update 130. It allows an authenticated WebGUI user with privileges to execute Stored Cross-site Scripting in the Captive Portal page.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
IPFire Firewall 跨站脚本漏洞
Vulnerability Description
IPFire Firewall是IPFire组织的一套开源的基于Linux的防火墙系统。 IPFire Firewall 2.21 存在跨站脚本漏洞,该漏洞源于“Title of Login Page”文本框或“TITLE”参数。该漏洞允许经过身份验证的 WebGUI 用户有权在 Captive Portal 页面中执行存储的跨站点脚本。
CVSS Information
N/A
Vulnerability Type
N/A