CVE-2022-23993: XSS
Published Jan 26, 2022
·Updated
/usr/local/www/pkg.php in pfSense CE before 2.6.0 and pfSense Plus before 22.01 uses $REQUEST['pkgfilter'] in a PHP echo call, causing XSS.
Affected Software
2 affected components
pfSense pfSense<2.6.0
pfSense pfSense Plus<22.01
Remediation
Event History
Jan 26, 2022
CVE Published
via MITRE·06:22 PM
Data Sourced
via MITRE·06:22 PM
Description
Frequently Asked Questions
1
What is the vulnerability ID for this pfSense vulnerability?
The vulnerability ID for this pfSense vulnerability is CVE-2022-23993.
2
What is the affected software for this vulnerability?
The affected software for this vulnerability is pfSense CE before 2.6.0 and pfSense Plus before 22.01.
3
What is the severity of CVE-2022-23993?
The severity of CVE-2022-23993 is medium with a CVSS score of 6.1.
4
How does CVE-2022-23993 impact pfSense?
CVE-2022-23993 allows for cross-site scripting (XSS) attacks on /usr/local/www/pkg.php in pfSense CE before 2.6.0 and pfSense Plus before 22.01.
5
How can I fix CVE-2022-23993 in pfSense?
To fix CVE-2022-23993 in pfSense, you should update to version 2.6.0 for pfSense CE or version 22.01 for pfSense Plus.