CVE-2019-25395 – Smoothwall Express 3.1 ‘preferences.cgi’ Cross-Site Scripting
CVE ID : CVE-2019-25395
Published : Feb. 16, 2026, 6:19 p.m. | 16 minutes ago
Description : Smoothwall Express 3.1-SP4-polar-x86_64-update9 contains multiple stored cross-site scripting vulnerabilities in the preferences.cgi script that allow attackers to inject malicious scripts through the HOSTNAME, KEYMAP, and OPENNESS parameters. Attackers can submit POST requests with script payloads to preferences.cgi to store malicious code that executes in the browsers of users accessing the preferences page.
Severity: 7.2 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more…