XSS Vulnerability in pfSense FreeRADIUS Package
CVE-2019-18667

6.1MEDIUM

Key Information:

Vendor

Pfsense

Vendor
CVE Published:
2 November 2019

What is CVE-2019-18667?

The FreeRADIUS package within pfSense on FreeBSD prior to version 0.15.7_3 contains a Cross-Site Scripting (XSS) vulnerability. An attacker can exploit this flaw by injecting a malicious payload into the username or password fields. If a user interacts with the compromised fields, arbitrary JavaScript code can be executed in the context of the victim's browser, potentially leading to unauthorized actions, data theft, or other malicious activities.

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.