First published: Wed Aug 09 2023(Updated: )
A reflected cross-site scripting (XSS) vulnerability in the component /ui/diagnostics/log/core/ of OPNsense Community Edition before 23.7 and Business Edition before 23.4.2 allows attackers to inject arbitrary JavaScript via the URL path.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
OPNsense OPNsense | <23.7 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-39000 is a reflected cross-site scripting (XSS) vulnerability in the component /ui/diagnostics/log/core/ of OPNsense before version 23.7.
The CVE-2023-39000 vulnerability allows attackers to inject arbitrary JavaScript through the URL path, leading to potential cross-site scripting attacks.
CVE-2023-39000 has a severity score of 6.1, which is classified as medium.
To fix CVE-2023-39000, you should update OPNsense to version 23.7 or above, as this vulnerability has been addressed in that release.
Yes, you can find more information about CVE-2023-39000 and its remediation in the references provided: [Github Commit](https://github.com/opnsense/core/commit/d1f350ce70e477adc86d445f5cda9b24f9ff0168) and [LogicalTrust Blog](https://logicaltrust.net/blog/2023/08/opnsense.html).