CVE-2020-11457: XSS
Published Apr 1, 2020
·Updated
pfSense before 2.4.5 has stored XSS in systemusermanageraddprivs.php in the WebGUI via the descr parameter (aka full name) of a user.
Affected Software
1 affected component
Netgate pfSense<2.4.5
Remediation
Event History
Apr 1, 2020
CVE Published
via MITRE·03:47 PM
Data Sourced
via MITRE·03:47 PM
Description
Frequently Asked Questions
1
What is the vulnerability ID of the stored XSS vulnerability in pfSense?
The vulnerability ID is CVE-2020-11457.
2
What is the affected software?
The affected software is pfSense versions up to 2.4.5.
3
What is the severity of CVE-2020-11457?
The severity of CVE-2020-11457 is medium.
4
How can the vulnerability be exploited?
The vulnerability can be exploited through the descr parameter (full name) of a user in the WebGUI of pfSense.
5
Are there any known fixes for CVE-2020-11457?
Yes, the fix for CVE-2020-11457 is included in pfSense version 2.4.5.