CVE-2025-11189 | Synchroweb Kiwire Captive Portal 3.6 Parameter login-url cross site scripting
A vulnerability was found in Synchroweb Kiwire Captive Portal 3.6. It has been classified as problematic. Affected by this vulnerability is an unknown functionality of the component Parameter Handler. The manipulation of the argument login-url leads to cross site scripting.
This vulnerability is traded as CVE-2025-11189. It is possible to initiate the attack remotely. There is no exploit available.