Cross-Site Scripting in OPNsense Cron Component by OPNsense
CVE-2023-39007

9.6CRITICAL

Key Information:

Vendor

Opnsense

Status
Vendor
CVE Published:
9 August 2023

What is CVE-2023-39007?

A security flaw has been identified in the Cron component of OPNsense, affecting both the Community and Business Editions. The vulnerability arises from improper handling of user inputs in the app/controllers/OPNsense/Cron/ItemController.php file. Malicious actors could exploit this weakness to execute arbitrary JavaScript code in the context of an unwitting user's session, potentially leading to unauthorized actions or data exposure. Patching is recommended to mitigate associated risks.

References

EPSS Score

48% chance of being exploited in the next 30 days.

CVSS V3.1

Score:
9.6
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.