PT-2021-23680 · Opnsense · Opnsense

Arthur Naullet

·

Published

2021-11-08

·

Updated

2022-07-28

·

CVE-2021-42770

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions OPNsense versions prior to 21.7.4
Description A Cross-site scripting (XSS) vulnerability was discovered in OPNsense via the LDAP attribute return in the authentication tester. This issue allows for potential exploitation through the LDAP attribute return, which is used in the authentication tester.
Recommendations For OPNsense versions prior to 21.7.4, update to version 21.7.4 or later to resolve the issue. As a temporary workaround, consider restricting access to the authentication tester until a patch is applied.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-42770
GHSA-R32J-XGG3-W2RW

Affected Products

Opnsense