First published: Thu Dec 15 2022(Updated: )
Cross Site Scripting (XSS) vulnerability in Netgate pf Sense 2.4.4-Release-p3 and Netgate ACME package 0.6.3 allows remote attackers to to run arbitrary code via the RootFolder field to acme_certificate_edit.php page of the ACME package.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Netgate ACME | =0.6.3 | |
Netgate pfSense | =2.4.4-p3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2020-21219 is medium.
CVE-2020-21219 is a Cross Site Scripting (XSS) vulnerability in Netgate pfSense 2.4.4-Release-p3 and Netgate ACME package 0.6.3 that allows remote attackers to run arbitrary code via the RootFolder field to acme_certificate_edit.php page of the ACME package.
CVE-2020-21219 affects Netgate ACME package 0.6.3.
CVE-2020-21219 affects Netgate pfSense 2.4.4-Release-p3.
The CWE for CVE-2020-21219 is CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')