CVE-2019-25376: OPNsense 19.1 Reflected XSS via proxy endpoint
OPNsense 19.1 contains a reflected cross-site scripting vulnerability that allows unauthenticated attackers to inject malicious scripts by submitting crafted payloads through the ignoreLogACL parameter. Attackers can send POST requests to the proxy endpoint with JavaScript code in the ignoreLogACL parameter to execute arbitrary scripts in users' browsers.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2019-25376?
CVE-2019-25376 is classified as a Medium severity vulnerability due to its potential for exploitation through reflected cross-site scripting.
How do I fix CVE-2019-25376?
To mitigate CVE-2019-25376, it's recommended to upgrade to the latest version of OPNsense that includes patches for this vulnerability.
What can attackers do with CVE-2019-25376?
Attackers exploiting CVE-2019-25376 can inject malicious scripts into the application through crafted payloads submitted via the ignoreLogACL parameter.
Which software versions are affected by CVE-2019-25376?
CVE-2019-25376 affects OPNsense version 19.1.
Is user authentication required to exploit CVE-2019-25376?
No, CVE-2019-25376 can be exploited by unauthenticated attackers.