CVE-2022-29273: XSS
Published Feb 22, 2023
·Updated
pfSense CE through 2.6.0 and pfSense Plus before 22.05 allow XSS in the WebGUI via URL Table Alias URL parameters.
Affected Software
2 affected components
Netgate pfSense<=2.6.0
Netgate pfSense<22.05
Remediation
Patch Available
Event History
Feb 22, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Frequently Asked Questions
1
What is the vulnerability ID of this security issue?
The vulnerability ID of this security issue is CVE-2022-29273.
2
What is the title of this vulnerability?
The title of this vulnerability is 'pfSense CE through 2.6.0 and pfSense Plus before 22.05 allow XSS in the WebGUI via URL Table Alias U…'
3
What is the severity rating of CVE-2022-29273?
The severity rating of CVE-2022-29273 is medium (6.1).
4
Which software versions are affected by this vulnerability?
pfSense CE through 2.6.0 and pfSense Plus before 22.05 are affected by this vulnerability.
5
How can this vulnerability be exploited?
This vulnerability can be exploited via URL Table Alias URL parameters in the pfSense WebGUI, allowing for cross-site scripting (XSS).