Cross-site Scripting Vulnerability in pfSense Products by Netgate
CVE-2021-20729

6.1MEDIUM

Key Information:

Vendor

Pfsense

Vendor
CVE Published:
31 March 2022

What is CVE-2021-20729?

A cross-site scripting vulnerability exists in pfSense CE and pfSense Plus, where a remote attacker can inject arbitrary scripts through malicious URLs. This can lead to unauthorized actions performed by users, compromising the security of the affected systems. Users of pfSense CE versions 2.5.2 and earlier, as well as pfSense Plus versions 21.05 and earlier, are advised to update to the latest software versions to mitigate potential exploits.

Affected Version(s)

pfSense CE and pfSense Plus pfSense CE software versions 2.5.2 and earlier, and pfSense Plus software versions 21.05 and earlier

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.