CVE-2025-50975

IPFire 2.29 web-based firewall interface (firewall.cgi) fails to sanitize several rule parameters such as PROT, SRC_PORT, TGT_PORT, dnatport, key, ruleremark, src_addr, std_net_tgt, and tgt_addr, allowing an authenticated administrator to inject persistent JavaScript. This stored XSS payload is executed whenever another admin views the firewall rules page, enabling session hijacking, unauthorized actions within the interface, or further internal pivoting. Exploitation requires only high-privilege GUI access, and the complexity of the attack is low.
Configurations

Configuration 1 (hide)

cpe:2.3:a:ipfire:ipfire:2.29:-:*:*:*:*:*:*

History

No history.

Information

Published : 2025-08-26 19:15

Updated : 2025-09-09 18:55


NVD link : CVE-2025-50975

Mitre link : CVE-2025-50975

CVE.ORG link : CVE-2025-50975


JSON object : View

Products Affected

ipfire

  • ipfire
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')