CVE-2019-16914: XSS
Published Sep 26, 2019
·Updated
An XSS issue was discovered in pfSense through 2.4.4-p3. In servicescaptiveportalmac.php, the username and delmac parameters are displayed without sanitization.
Affected Software
5 affected components
Netgate pfSense<2.4.4
Netgate pfSense=2.4.4
Netgate pfSense=2.4.4-p1
Netgate pfSense=2.4.4-p2
Netgate pfSense=2.4.4-p3
Remediation
Event History
Sep 26, 2019
CVE Published
via MITRE·05:38 PM
Data Sourced
via MITRE·05:38 PM
Description
Frequently Asked Questions
1
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2019-16914.
2
What is the severity of CVE-2019-16914?
The severity of CVE-2019-16914 is medium.
3
What is the affected software for CVE-2019-16914?
The affected software for CVE-2019-16914 is Netgate pfSense version 2.4.4-p3 and earlier.
4
What is the Common Weakness Enumeration (CWE) ID for this vulnerability?
The Common Weakness Enumeration (CWE) ID for CVE-2019-16914 is CWE-79.
5
How can I fix CVE-2019-16914?
To fix CVE-2019-16914, it is recommended to update to a patched version of Netgate pfSense.