CVE detail
CVE-2020-19204 — CVE-2020-19204
Published 2021-07-12 · Modified 2026-06-17 · Vendor ipfire · Product ipfire · Source nvd
MEDIUM
severity
CVSS-derived band
0.0074
EPSS probability
exploitation probability, 30d
51.0%
EPSS percentile
percentile vs all CVEs
NOT LISTED
CISA KEV
known exploited catalog
Description
An authenticated Stored Cross-Site Scriptiong (XSS) vulnerability exists in Lightning Wire Labs IPFire 2.21 (x86_64) - Core Update 130 in the "routing.cgi" Routing Table Entries via the "Remark" text box or "remark" parameter. It allows an authenticated WebGUI user to execute Stored Cross-site Scripting in the Routing Table Entries.
Remediation
No vendor-published fix data in our corpus for this CVE. Check the references below or the vendor's PSIRT / security advisories page.
References