CVE Database
/

CVE-2022-36368

Back to search

CVE-2022-36368

Published: Oct 24, 2022

Modified: May 7, 2025

PUBLISHED

Description

Multiple stored cross-site scripting vulnerabilities in the web user interface of IPFire versions prior to 2.27 allows a remote authenticated attacker with administrative privilege to inject an arbitrary script.

VendorProductVersions

IPFire Project

IPFire

affected
versions prior to 2.27

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now