IPFire versions prior to 2.29 (Core Update 198) contain a stored cross-site scripting (XSS) vulnerability that allows an authenticated attacker to inject arbitrary JavaScript code through the SRC, DST, and COMMENT parameters when creating a time constraint rule. When a user adds a time constraint rule the application issues an HTTP POST request to /cgi-bin/urlfilter.cgi with the MODE parameter set to TIMECONSTRAINT and the source hostnames/IPs, destination, and remark provided in the SRC, DST, and COMMENT parameters respectively. The values of these parameters are stored and later rendered in the web interface without proper sanitation or encoding, allowing injected scripts to execute in the context of other users who view the affected time constraint entry.
References
| Link | Resource |
|---|---|
| https://bugzilla.ipfire.org/show_bug.cgi?id=13889 | Issue Tracking Third Party Advisory |
| https://www.ipfire.org/blog/ipfire-2-29-core-update-198-released | Release Notes |
| https://www.vulncheck.com/advisories/ipfire-stored-xss-via-time-constraint-rule-url-filter | Third Party Advisory |
Configurations
Configuration 1 (hide)
|
History
03 Nov 2025, 17:02
| Type | Values Removed | Values Added |
|---|---|---|
| First Time |
Ipfire ipfire
Ipfire |
|
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 5.4 |
| References | () https://bugzilla.ipfire.org/show_bug.cgi?id=13889 - Issue Tracking, Third Party Advisory | |
| References | () https://www.ipfire.org/blog/ipfire-2-29-core-update-198-released - Release Notes | |
| References | () https://www.vulncheck.com/advisories/ipfire-stored-xss-via-time-constraint-rule-url-filter - Third Party Advisory | |
| CPE | cpe:2.3:a:ipfire:ipfire:2.29:core_update183:*:*:*:*:*:* cpe:2.3:a:ipfire:ipfire:2.29:core_update195:*:*:*:*:*:* cpe:2.3:a:ipfire:ipfire:2.29:core_update189:*:*:*:*:*:* cpe:2.3:a:ipfire:ipfire:2.29:core_update188:*:*:*:*:*:* cpe:2.3:a:ipfire:ipfire:2.29:core_update197:*:*:*:*:*:* cpe:2.3:a:ipfire:ipfire:*:*:*:*:*:*:*:* cpe:2.3:a:ipfire:ipfire:2.29:core_update187:*:*:*:*:*:* cpe:2.3:a:ipfire:ipfire:2.29:core_update185:*:*:*:*:*:* cpe:2.3:a:ipfire:ipfire:2.29:core_update191:*:*:*:*:*:* cpe:2.3:a:ipfire:ipfire:2.29:core_update186:*:*:*:*:*:* cpe:2.3:a:ipfire:ipfire:2.29:core_update194:*:*:*:*:*:* cpe:2.3:a:ipfire:ipfire:2.29:core_update184:*:*:*:*:*:* cpe:2.3:a:ipfire:ipfire:2.29:core_update192:*:*:*:*:*:* cpe:2.3:a:ipfire:ipfire:2.29:core_update193:*:*:*:*:*:* cpe:2.3:a:ipfire:ipfire:2.29:core_update196:*:*:*:*:*:* cpe:2.3:a:ipfire:ipfire:2.29:core_update190:*:*:*:*:*:* |
28 Oct 2025, 15:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2025-10-28 15:16
Updated : 2025-11-03 17:02
NVD link : CVE-2025-34314
Mitre link : CVE-2025-34314
CVE.ORG link : CVE-2025-34314
JSON object : View
Products Affected
ipfire
- ipfire
CWE
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
