CVE-2022-42247: XSS
Published Oct 3, 2022
·Updated
pfSense v2.5.2 was discovered to contain a cross-site scripting (XSS) vulnerability in the browser.php component. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into a file name.
Affected Software
1 affected component
pfSense pfSense=2.5.2
Remediation
Event History
Oct 3, 2022
CVE Published
via MITRE·03:31 PM
Data Sourced
via MITRE·03:31 PM
Description
Data Sourced
via NVD·04:15 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the vulnerability ID?
The vulnerability ID is CVE-2022-42247.
2
What is the severity of CVE-2022-42247?
The severity of CVE-2022-42247 is medium with a CVSS score of 6.1.
3
What is the affected software version?
The affected software version is pfSense v2.5.2.
4
What is the description of the vulnerability?
The vulnerability is a cross-site scripting (XSS) vulnerability in the browser.php component of pfSense v2.5.2.
5
How can attackers exploit CVE-2022-42247?
Attackers can exploit CVE-2022-42247 by injecting a crafted payload into a file name, allowing them to execute arbitrary web scripts or HTML.