CVE-2015-4029: XSS
Published Aug 18, 2015
·Updated
Cross-site scripting (XSS) vulnerability in the WebGUI in pfSense before 2.2.3 allows remote attackers to inject arbitrary web script or HTML via the zone parameter in a del action to servicescaptiveportalzones.php.
Affected Software
1 affected component
Netgate pfSense<=2.2.2
Event History
Aug 18, 2015
CVE Published
via MITRE·03:00 PM
Data Sourced
via MITRE·03:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2015-4029?
CVE-2015-4029 has a moderate severity rating due to the potential for remote code execution through XSS attacks.
2
How do I fix CVE-2015-4029?
To fix CVE-2015-4029, update pfSense to version 2.2.3 or later, which includes the patch for this vulnerability.
3
What is the impact of CVE-2015-4029?
The impact of CVE-2015-4029 includes the potential for attackers to execute arbitrary JavaScript or HTML in users' browsers.
4
Which versions of pfSense are affected by CVE-2015-4029?
CVE-2015-4029 affects all pfSense versions prior to 2.2.3.
5
Can CVE-2015-4029 be exploited without authentication?
Yes, CVE-2015-4029 can be exploited by remote attackers without requiring authentication.