CVE-2019-12584: XSS
Apcupsd 0.3.915, as used in pfSense through 2.4.4-RELEASE-p3 and other products, has an XSS issue in apcupsdstatus.php.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2019-12584?
CVE-2019-12584 is a Cross-Site Scripting (XSS) vulnerability in Apcupsd 0.3.91_5, which is used in pfSense through 2.4.4-RELEASE-p3 and other products.
What is the severity of CVE-2019-12584?
The severity of CVE-2019-12584 is medium (CVSS score: 6.1).
How does CVE-2019-12584 affect Apcupsd and pfSense?
CVE-2019-12584 affects Apcupsd 0.3.91_5 in pfSense through 2.4.4-RELEASE-p3 and other products, allowing for Cross-Site Scripting (XSS) attacks through apcupsd_status.php.
What is the fix for CVE-2019-12584?
To fix CVE-2019-12584, it is recommended to update Apcupsd to a version that addresses the XSS issue, such as Apcupsd 0.3.91_6 or later.
Is there any additional information about CVE-2019-12584?
Yes, you can find additional information about CVE-2019-12584 on the CTRSec website, GitHub repository, and the pfSense Redmine issue.