CVE-2022-36368

Publication date

2022-10-24 00:00:00

Family

jpcert

State

PUBLISHED

Description

Multiple stored cross-site scripting vulnerabilities in the web user interface of IPFire versions prior to 2.27 allows a remote authenticated attacker with administrative privilege to inject an arbitrary script.