Reflected Cross-Site Scripting Vulnerability in OPNsense Community and Business Editions
CVE-2023-39000

6.1MEDIUM

Key Information:

Vendor

Opnsense

Status
Vendor
CVE Published:
9 August 2023

What is CVE-2023-39000?

A reflected cross-site scripting (XSS) vulnerability exists in the OPNsense software, specifically within the /ui/diagnostics/log/core/ component. This weakness affects both the Community Edition prior to version 23.7 and the Business Edition prior to version 23.4.2. Attackers can exploit this vulnerability by injecting arbitrary JavaScript code through the URL path, potentially allowing unauthorized access to sensitive information or enabling further malicious actions.

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.