PT-2023-12967 · Unknown · Pfsense Ce+1

Published

2023-02-22

·

Updated

2023-04-10

·

CVE-2022-29273

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions pfSense CE versions 2.6.0 and earlier pfSense Plus versions prior to 22.05
Description The issue allows for XSS in the WebGUI via URL Table Alias URL parameters. This means an attacker could potentially inject malicious scripts into the web interface of the affected software, exploiting the URL parameter in the URL Table Alias functionality.
Recommendations For pfSense CE versions 2.6.0 and earlier, update to a version later than 2.6.0. For pfSense Plus versions prior to 22.05, update to version 22.05 or later. As a temporary workaround, consider restricting access to the WebGUI to minimize the risk of exploitation.

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2022-29273

Affected Products

Pfsense Ce
Pfsense Plus