CVE-2020-19203: XSS
Published Jul 12, 2021
·Updated
An authenticated Cross-Site Scripting (XSS) vulnerability was found in widgets/widgets/wakeonlanwidget.php, a component of the pfSense software WebGUI, on version 2.4.4-p2 and earlier. The widget did not encode the descr (description) parameter of wake-on-LAN entries in its output, leading to a possible stored XSS.
Affected Software
4 affected components
Netgate pfSense<2.4.4
Netgate pfSense=2.4.4
Netgate pfSense=2.4.4-p1
Netgate pfSense=2.4.4-p2
Event History
Jul 12, 2021
CVE Published
via MITRE·03:39 PM
Data Sourced
via MITRE·03:39 PM
Description
Frequently Asked Questions
1
What is the vulnerability ID for this cross-site scripting vulnerability?
The vulnerability ID for this cross-site scripting vulnerability is CVE-2020-19203.
2
What is the severity of CVE-2020-19203?
The severity of CVE-2020-19203 is medium with a CVSS score of 5.4.
3
Which software is affected by CVE-2020-19203?
CVE-2020-19203 affects the pfSense software WebGUI version 2.4.4-p2 and earlier.
4
How can I fix CVE-2020-19203?
To fix CVE-2020-19203, it is recommended to update pfSense to version 2.4.4-p3 or later.
5
Where can I find more information about CVE-2020-19203?
You can find more information about CVE-2020-19203 in the following references: [link1], [link2], [link3].