PT-2026-8248 · Opnsense · Opnsense

Ozer Goker

·

Published

2026-02-15

·

Updated

2026-02-15

·

CVE-2019-25376

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions OPNsense version 19.1
Description OPNsense version 19.1 contains a reflected cross-site scripting issue that allows unauthenticated attackers to inject malicious scripts. Attackers can submit crafted payloads through the ignoreLogACL parameter to execute arbitrary scripts in users' browsers. This is achieved by sending POST requests to the proxy endpoint with JavaScript code in the ignoreLogACL parameter. The vulnerable API endpoint is '/proxy'.
Recommendations Apply a fix to address the reflected cross-site scripting issue in the ignoreLogACL parameter of the proxy endpoint.

Exploit

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2019-25376

Affected Products

Opnsense