PT-2021-10306 · Netgate · Pfsense

Dharmesh Baskaran

·

Published

2021-07-12

·

Updated

2021-09-14

·

CVE-2020-19201

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions: Netgate pfSense versions 2.4.4-p2 and earlier
Description: A Stored Cross-Site Scripting (XSS) issue was found in the status filter reload.php page of the pfSense software WebGUI. The page did not properly encode output from the filter reload process, allowing a stored XSS attack via the descr parameter on NAT rules.
Recommendations: For Netgate pfSense versions 2.4.4-p2 and earlier, update to a version that includes the fix for this issue to prevent stored XSS attacks. As a temporary workaround, consider restricting access to the status filter reload.php page and avoiding the use of the descr parameter on NAT rules until a patch is available.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-19201

Affected Products

Pfsense