CVE-2023-42325: XSS
Published Nov 14, 2023
·Updated
Cross Site Scripting (XSS) vulnerability in Netgate pfSense v.2.7.0 allows a remote attacker to gain privileges via a crafted url to the statuslogsfilterdynamic.php page.
Affected Software
3 affected components
Netgate pfSense=2.7.0
pfSense pfSense=2.7.0
pfSense pfSense Plus=23.05.01
Event History
Nov 14, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Dec 12, 2023
News Published
02:00 PM
Frequently Asked Questions
1
What is the severity of CVE-2023-42325?
The severity of CVE-2023-42325 is medium with a CVSS score of 5.4.
2
How does the Cross Site Scripting (XSS) vulnerability in Netgate pfSense v.2.7.0 affect the system?
The vulnerability allows a remote attacker to gain privileges by exploiting a crafted URL to the status_logs_filter_dynamic.php page.
3
How can I fix the Cross Site Scripting (XSS) vulnerability in Netgate pfSense v.2.7.0?
Upgrade to a patched version of Netgate pfSense that is not affected by the vulnerability.