CVE-2019-16915: Path Traversal
Published Sep 26, 2019
·Updated
An issue was discovered in pfSense through 2.4.4-p3. widgets/widgets/picture.widget.php uses the widgetkey parameter directly without sanitization (e.g., a basename call) for a pathname to filegetcontents or fileputcontents.
Affected Software
5 affected components
Netgate pfSense<2.4.4
Netgate pfSense=2.4.4
Netgate pfSense=2.4.4-p1
Netgate pfSense=2.4.4-p2
Netgate pfSense=2.4.4-p3
Remediation
Event History
Sep 26, 2019
CVE Published
via MITRE·05:38 PM
Data Sourced
via MITRE·05:38 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2019-16915?
The severity of CVE-2019-16915 is critical (9.8).
2
What is the affected software of CVE-2019-16915?
The affected software of CVE-2019-16915 is Netgate pfSense version 2.4.4-p3.
3
How does CVE-2019-16915 impact the affected software?
CVE-2019-16915 allows an attacker to provide a specially crafted widgetkey parameter, leading to untrusted input being passed to file_get_contents or file_put_contents functions.
4
Are there any fixes or patches available for CVE-2019-16915?
Yes, patches are available for CVE-2019-16915. Please refer to the references for more details.
5
Where can I find more information about CVE-2019-16915?
You can find more information about CVE-2019-16915 in the references section.