CVE-2022-36368
24.10.2022, 14:15
Multiple stored cross-site scripting vulnerabilities in the web user interface of IPFire versions prior to 2.27 allows a remote authenticated attacker with administrative privilege to inject an arbitrary script.
| Vendor | Product | Version |
|---|---|---|
| ipfire | ipfire | 𝑥 < 2.27 |
| ipfire | ipfire | 2.27:core_update159 |
| ipfire | ipfire | 2.27:core_update160 |
| ipfire | ipfire | 2.27:core_update161 |
| ipfire | ipfire | 2.27:core_update162 |
| ipfire | ipfire | 2.27:core_update163 |
| ipfire | ipfire | 2.27:core_update164 |
| ipfire | ipfire | 2.27:core_update165 |
| ipfire | ipfire | 2.27:core_update166 |
| ipfire | ipfire | 2.27:core_update167 |
𝑥
= Vulnerable software versions
References