CVE-2021-20729: XSS
Cross-site scripting vulnerability in pfSense CE and pfSense Plus (pfSense CE software versions 2.5.2 and earlier, and pfSense Plus software versions 21.05 and earlier) allows a remote attacker to inject an arbitrary script via a malicious URL.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2021-20729?
The severity of CVE-2021-20729 is medium with a severity value of 6.1.
How does CVE-2021-20729 affect pfSense CE?
CVE-2021-20729 affects pfSense CE versions 2.5.2 and earlier, allowing a remote attacker to inject an arbitrary script via a malicious URL.
How does CVE-2021-20729 affect pfSense Plus?
CVE-2021-20729 affects pfSense Plus versions 21.05 and earlier, allowing a remote attacker to inject an arbitrary script via a malicious URL.
What is the Common Weakness Enumeration (CWE) for CVE-2021-20729?
The Common Weakness Enumeration (CWE) for CVE-2021-20729 is CWE-79.
Where can I find more information about CVE-2021-20729?
You can find more information about CVE-2021-20729 at the following references: [link1](https://docs.netgate.com/downloads/pfSense-SA-21_02.captiveportal.asc), [link2](https://jvn.jp/en/jp/JVN87751554/index.html).