Cross-Site Scripting in OPNsense Cron Component by OPNsense
CVE-2023-39007
9.6CRITICAL
What is CVE-2023-39007?
A security flaw has been identified in the Cron component of OPNsense, affecting both the Community and Business Editions. The vulnerability arises from improper handling of user inputs in the app/controllers/OPNsense/Cron/ItemController.php file. Malicious actors could exploit this weakness to execute arbitrary JavaScript code in the context of an unwitting user's session, potentially leading to unauthorized actions or data exposure. Patching is recommended to mitigate associated risks.
