Actions
Bug #16413
closedPotential stored XSS in the Status_Traffic_Totals package
Start date:
Due date:
% Done:
100%
Estimated time:
Plus Target Version:
Affected Version:
Affected Plus Version:
Affected Architecture:
Description
There is a potential stored cross-site scripting vulnerability in the Status_Traffic_Totals package:
In /usr/local/www/status_traffic_totals.php
, the value of the start-day
parameter is printed back to the user without validation or encoding. This value can be saved as a default when visiting the Status Traffic Totals page.
Reported by Alex Williams of Pellera Technology via VulnCheck, CVE-2025-34174
Actions