CVE-2020-26693: XSS
Published Jun 1, 2021
·Updated
A stored cross-site scripting (XSS) vulnerability was discovered in pfSense 2.4.5-p1 which allows an authenticated attacker to execute arbitrary web scripts via exploitation of the loadbalancermonitor.php function.
Affected Software
1 affected component
pfSense pfSense=2.4.5-p1
Remediation
Event History
Jun 1, 2021
CVE Published
via MITRE·02:30 PM
Data Sourced
via MITRE·02:30 PM
Description
Frequently Asked Questions
1
What is CVE-2020-26693?
CVE-2020-26693 is a stored cross-site scripting (XSS) vulnerability discovered in pfSense 2.4.5-p1.
2
How severe is CVE-2020-26693?
CVE-2020-26693 has a severity rating of 5.4, which is considered medium.
3
How does CVE-2020-26693 affect pfSense?
CVE-2020-26693 allows an authenticated attacker to execute arbitrary web scripts in pfSense 2.4.5-p1.
4
How can an attacker exploit CVE-2020-26693?
An attacker can exploit CVE-2020-26693 by exploiting the load_balancer_monitor.php function in pfSense 2.4.5-p1.
5
Is there a fix available for CVE-2020-26693?
Yes, a fix for CVE-2020-26693 has been implemented in the pfSense 2.4.5-p1 release.