Project

General

Profile

Actions

Bug #16413

closed

Potential stored XSS in the Status_Traffic_Totals package

Added by Jim Pingle 6 days ago. Updated 3 days ago.

Status:
Resolved
Priority:
High
Assignee:
Category:
Status Traffic Totals
Target version:
-
Start date:
Due date:
% Done:

100%

Estimated time:
Plus Target Version:
Affected Version:
Affected Plus Version:
Affected Architecture:

Description

There is a potential stored cross-site scripting vulnerability in the Status_Traffic_Totals package:

In /usr/local/www/status_traffic_totals.php, the value of the start-day parameter is printed back to the user without validation or encoding. This value can be saved as a default when visiting the Status Traffic Totals page.

Reported by Alex Williams of Pellera Technology via VulnCheck, CVE-2025-34174

Actions

Also available in: Atom PDF