PT-2026-8243 · Opnsense · Opnsense

Ozer Goker

·

Published

2026-02-15

·

Updated

2026-02-15

·

CVE-2019-25371

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions OPNsense version 19.1
Description OPNsense version 19.1 has a reflected cross-site scripting issue. Unauthenticated attackers can inject malicious scripts due to inadequate input validation. Attackers can send specially crafted POST requests to the /diag ping.php endpoint, using the host parameter to include script payloads and execute arbitrary JavaScript in the browsers of users. The host parameter is the point of injection.
Recommendations Apply input validation to the host parameter in the /diag ping.php endpoint.

Exploit

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2019-25371

Affected Products

Opnsense