Kiwire Captive Portal Reflected Cross-Site Scripting Vulnerability
Vulnerability
A reflected cross-site scripting vulnerability has been identified in the Kiwire Captive Portal. This issue arises within the login-url parameter, allowing for the execution of JavaScript. The vulnerability affects Kiwire versions prior to 3.2.3.
Impact
Exploitation of this vulnerability allows for reflected cross-site scripting, where an attacker can inject malicious scripts that are executed in the context of the user's browser.
Remediation
Users can upgrade to Kiwire version 3.2.3 or later, where this vulnerability has been fixed.
Added: Oct 10, 2025, 11:25 AM
Updated: Oct 10, 2025, 11:25 AM
Vulnerability Rating
Custom Algorithm
spread
0.0impact
1.7exploitability
6.4remediation
0.0relevance
0.7threat
0.0urgency
2.9incentive
1.7Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
