CVE-2019-8953: XSS
The HAProxy package before 0.5916 for pfSense has XSS via the desc (aka Description) or tableactionsaclN parameter, related to haproxylisteners.php and haproxylistenersedit.php.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the vulnerability ID for this vulnerability?
The vulnerability ID for this vulnerability is CVE-2019-8953.
What is the severity of CVE-2019-8953?
The severity of CVE-2019-8953 is medium.
What is the affected software?
The affected software is Netgate Haproxy before version 0.59_16.
How does the vulnerability occur?
The vulnerability occurs via XSS (Cross-Site Scripting) through the desc or table_actionsaclN parameter in haproxy_listeners.php and haproxy_listeners_edit.php.
Are there any references for this vulnerability?
Yes, you can find references for this vulnerability at the following links: [1](https://cxsecurity.com/issue/WLB-2019020153), [2](https://github.com/pfsense/FreeBSD-ports/commit/2dded47b3202dfdf89aa96f84bf701b3d5acbe6c), [3](https://github.com/pfsense/FreeBSD-ports/commit/3b40366aca55910b224ecf49d3fdacc9ad6c04f5).