CVE-2023-39006: XSS
The Crash Reporter (crashreporter.php) component of OPNsense Community Edition before 23.7 and Business Edition before 23.4.2 mishandles input sanitization.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2023-39006?
CVE-2023-39006 is a vulnerability in the Crash Reporter component of OPNsense Community Edition and Business Edition that mishandles input sanitization.
What is the severity of CVE-2023-39006?
The severity of CVE-2023-39006 is medium with a severity value of 5.4.
How does CVE-2023-39006 affect OPNsense?
CVE-2023-39006 affects OPNsense Community Edition before 23.7 and Business Edition before 23.4.2.
How can I fix CVE-2023-39006?
To fix CVE-2023-39006, you should update OPNsense to version 23.7 (for Community Edition) or version 23.4.2 (for Business Edition).
Where can I find more information about CVE-2023-39006?
You can find more information about CVE-2023-39006 at the following references: [GitHub](https://github.com/opnsense/core/commit/1c05a19d9d52c7bfa4ac52114935d9fe76d5d181) and [Logical Trust](https://logicaltrust.net/blog/2023/08/opnsense.html).