Back

MEDIUM

Smoothwall Express 3.1 'dmzholes.cgi' Cross-Site Scripting

Published Feb 16, 2026

Description

Smoothwall Express 3.1-SP4-polar-x86_64-update9 contains multiple reflected cross-site scripting vulnerabilities in the dmzholes.cgi script that allow attackers to inject malicious scripts through unvalidated parameters. Attackers can submit POST requests with script payloads in the SRC_IP, DEST_IP, or COMMENT parameters to execute arbitrary JavaScript in users' browsers.

Affected products

Remediation

No remediation recorded yet.

References (4)

Change history (0)

No recorded changes yet.

Sources

CVE.org / MITRE

Status PUBLISHED
Assigner VulnCheck
Published Feb 16, 2026
Updated Mar 5, 2026
Reserved Feb 16, 2026

CISA Vulnrichment

Updated Feb 17, 2026

NVD

Status Analyzed
Modified Jun 17, 2026

Red Hat

No data

ENISA EUVD

Assigner VulnCheck
Published Feb 16, 2026
Updated Mar 5, 2026

GitHub

No data