CVE-2019-25373: OPNsense 19.1 Stored XSS via firewall_rules_edit.php
OPNsense 19.1 contains a stored cross-site scripting vulnerability that allows authenticated attackers to inject malicious scripts by submitting crafted input to the category parameter. Attackers can send POST requests to firewallrulesedit.php with script payloads in the category field to execute arbitrary JavaScript in the browsers of other users accessing firewall rule pages.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2019-25373?
CVE-2019-25373 is classified as a high severity vulnerability due to its potential impact on the application.
How do I fix CVE-2019-25373?
To fix CVE-2019-25373, update OPNsense to the latest version where this vulnerability has been patched.
Who is affected by CVE-2019-25373?
CVE-2019-25373 affects all users of OPNsense version 19.1.
What type of vulnerability is CVE-2019-25373?
CVE-2019-25373 is a stored cross-site scripting vulnerability.
What is the exploit vector for CVE-2019-25373?
The exploit vector for CVE-2019-25373 involves sending crafted input to the category parameter in POST requests to firewall_rules_edit.php.