CVE-2014-4687: XSS
Multiple cross-site scripting (XSS) vulnerabilities in pfSense before 2.1.4 allow remote attackers to inject arbitrary web script or HTML via (1) the starttime0 parameter to firewallschedule.php, (2) the rssfeed parameter to rss.widget.php, (3) the servicestatusfilter parameter to servicesstatus.widget.php, (4) the txtRecallBuffer parameter to exec.php, or (5) the HTTP Referer header to log.widget.php.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2014-4687?
CVE-2014-4687 is classified with a medium severity due to the potential for cross-site scripting attacks.
How do I fix CVE-2014-4687?
To fix CVE-2014-4687, upgrade pfSense to version 2.1.4 or later.
Which versions of pfSense are affected by CVE-2014-4687?
pfSense versions prior to 2.1.4, specifically 2.1.3 and earlier, are affected by CVE-2014-4687.
What types of attacks can occur due to CVE-2014-4687?
CVE-2014-4687 can lead to arbitrary web script or HTML injection, resulting in cross-site scripting vulnerabilities.
Is there a workaround for CVE-2014-4687 if I cannot upgrade?
There are no known workarounds for CVE-2014-4687; upgrading is the only effective solution.