CVE-2019-25377: OPNsense 19.1 Reflected XSS via system_advanced_sysctl.php
OPNsense 19.1 contains a reflected cross-site scripting vulnerability in the systemadvancedsysctl.php endpoint that allows attackers to inject malicious scripts via the value parameter. Attackers can craft POST requests with script payloads in the value parameter to execute JavaScript in the context of authenticated user sessions.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2019-25377?
CVE-2019-25377 is classified as a medium severity due to its potential for reflected cross-site scripting attacks.
How do I fix CVE-2019-25377?
To fix CVE-2019-25377, update OPNsense to the latest patched version that addresses this reflected XSS vulnerability.
What types of attacks can CVE-2019-25377 facilitate?
CVE-2019-25377 can facilitate reflected cross-site scripting attacks, allowing attackers to inject and execute malicious scripts in the context of a user's session.
Which version of OPNsense is affected by CVE-2019-25377?
The vulnerability CVE-2019-25377 affects OPNsense version 19.1.
How can I mitigate the risk of CVE-2019-25377?
To mitigate the risk of CVE-2019-25377, avoid using the vulnerable endpoint and ensure your system is updated regularly.