Multiple stored cross-site scripting vulnerabilities in the web user interface of IPFire versions prior to 2.27 allows a remote authenticated attacker with administrative privilege to inject an arbitrary script.
| Software | From | Fixed in |
|---|---|---|
| ipfire / ipfire | 2.27-core_update160 | 2.27-core_update160.x |
| ipfire / ipfire | 2.27-core_update161 | 2.27-core_update161.x |
| ipfire / ipfire | 2.27-core_update162 | 2.27-core_update162.x |
| ipfire / ipfire | 2.27-core_update163 | 2.27-core_update163.x |
| ipfire / ipfire | 2.27-core_update164 | 2.27-core_update164.x |
| ipfire / ipfire | 2.27-core_update165 | 2.27-core_update165.x |
| ipfire / ipfire | 2.27-core_update166 | 2.27-core_update166.x |
| ipfire / ipfire | 2.27-core_update167 | 2.27-core_update167.x |
| ipfire / ipfire | 2.27-core_update159 | 2.27-core_update159.x |
| ipfire / ipfire | - | 2.27 |