Reflected Cross-Site Scripting Vulnerability in OPNsense Community and Business Editions
CVE-2023-39000
6.1MEDIUM
What is CVE-2023-39000?
A reflected cross-site scripting (XSS) vulnerability exists in the OPNsense software, specifically within the /ui/diagnostics/log/core/ component. This weakness affects both the Community Edition prior to version 23.7 and the Business Edition prior to version 23.4.2. Attackers can exploit this vulnerability by injecting arbitrary JavaScript code through the URL path, potentially allowing unauthorized access to sensitive information or enabling further malicious actions.
