CVE-2023-39002: XSS
Published Aug 9, 2023
·Updated
A cross-site scripting (XSS) vulnerability in the act parameter of systemcertmanager.php in OPNsense Community Edition before 23.7 and Business Edition before 23.4.2 allows attackers to execute arbitrary web scripts or HTML via a crafted payload.
Affected Software
1 affected component
OPNsense OPNsense<23.7
Remediation
Event History
Aug 9, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Frequently Asked Questions
1
What is the vulnerability ID for this XSS vulnerability?
The vulnerability ID for this XSS vulnerability is CVE-2023-39002.
2
What is the affected software?
The affected software is OPNsense version up to 23.7.
3
What is the severity of CVE-2023-39002?
The severity of CVE-2023-39002 is medium with a CVSS score of 6.1.
4
How can an attacker exploit this vulnerability?
An attacker can exploit this vulnerability by injecting crafted payloads in the act parameter of system_certmanager.php.
5
Is there a fix available for CVE-2023-39002?
Yes, a fix is available. It is recommended to update to OPNsense version 23.7 or higher.