First published: Tue Nov 14 2023(Updated: )
Cross Site Scripting (XSS) vulnerability in Netgate pfSense v.2.7.0 allows a remote attacker to gain privileges via a crafted url to the status_logs_filter_dynamic.php page.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Netgate pfSense | =2.7.0 | |
pfSense pfSense | =2.7.0 | |
pfSense pfSense Plus | =23.05.01 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2023-42325 is medium with a CVSS score of 5.4.
The vulnerability allows a remote attacker to gain privileges by exploiting a crafted URL to the status_logs_filter_dynamic.php page.
Upgrade to a patched version of Netgate pfSense that is not affected by the vulnerability.