Medium severity6.1NVD Advisory· Published Feb 18, 2026· Updated Jun 17, 2026
CVE-2019-25396
CVE-2019-25396
Description
IPFire 2.21 Core Update 127 contains a reflected cross-site scripting vulnerability in the updatexlrator.cgi script that allows attackers to inject malicious scripts through POST parameters. Attackers can submit crafted requests with script payloads in the MAX_DISK_USAGE or MAX_DOWNLOAD_RATE parameters to execute arbitrary JavaScript in users' browsers.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3Patches
Vulnerability mechanics
References
4- www.exploit-db.com/exploits/46344nvdExploitThird Party AdvisoryVDB Entry
- www.vulncheck.com/advisories/ipfire-core-update-reflected-xss-via-updatexlratornvdBroken LinkThird Party Advisory
- downloads.ipfire.org/releases/ipfire-2.x/2.21-core127/ipfire-2.21.x86_64-full-core127.isonvdProduct
- www.ipfire.orgnvdProduct
News mentions
0No linked articles in our index yet.