Cross-Site Scripting in OPNsense Dashboard by Deciso
CVE-2023-44275

5.4MEDIUM

Key Information:

Vendor

Opnsense

Status
Vendor
CVE Published:
28 September 2023

What is CVE-2023-44275?

An XSS vulnerability exists in OPNsense versions prior to 23.7.5, specifically within the Lobby Dashboard due to improper handling of the 'column_count' parameter in 'index.php'. This flaw could allow an attacker to inject malicious scripts into the dashboard, potentially compromising user interactions. It is essential for users to update to the latest version to mitigate this security risk and protect their systems from potential exploitation.

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.