Project Subscriptions
No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Fri, 20 Feb 2026 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:o:smoothwall:smoothwall_express:3.1:sp4:*:*:-:*:*:* |
Tue, 17 Feb 2026 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 17 Feb 2026 09:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Smoothwall smoothwall Express
|
|
| Vendors & Products |
Smoothwall smoothwall Express
|
Mon, 16 Feb 2026 17:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Smoothwall Express 3.1-SP4-polar-x86_64-update9 contains a reflected cross-site scripting vulnerability that allows attackers to inject malicious scripts by manipulating the MACHINE and MACHINECOMMENT parameters. Attackers can send POST requests to the outgoing.cgi endpoint with script payloads to execute arbitrary JavaScript in users' browsers and steal session data. | |
| Title | Smoothwall Express 3.1 'outgoing.cgi' Cross-Site Scripting | |
| First Time appeared |
Smoothwall
Smoothwall smoothwall |
|
| Weaknesses | CWE-79 | |
| CPEs | cpe:2.3:a:smoothwall:smoothwall:3.1:*:*:*:*:*:*:* | |
| Vendors & Products |
Smoothwall
Smoothwall smoothwall |
|
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-02-17T15:00:51.195Z
Reserved: 2026-02-16T16:30:24.995Z
Link: CVE-2019-25385
Updated: 2026-02-17T15:00:42.462Z
Status : Analyzed
Published: 2026-02-16T18:19:42.967
Modified: 2026-02-20T16:26:41.493
Link: CVE-2019-25385
No data.
OpenCVE Enrichment
Updated: 2026-02-17T08:49:15Z