First of all, this vulnerability no longer exists in the current version 4.0.4-1, which was released on 07/19/2023.
What was this supposed vulnerability about?
It was a Reflective Cross-Site Scripting (XSS) vulnerability that allowed HTML/JavaScript code to be included in the login page with a manipulated URL parameter.
This vulnerability did not affect the security and functionality of ARP-GUARD at any time. Neither could databases be accessed, nor was there any possibility of data manipulation.
If you would like more detailed information, please do not hesitate to contact us.