CVE-2023-42327: XSS
Published Nov 14, 2023
·Updated
Cross Site Scripting (XSS) vulnerability in Netgate pfSense v.2.7.0 allows a remote attacker to gain privileges via a crafted URL to the getserviceproviders.php page.
Affected Software
3 affected components
Netgate pfSense=2.7.0
pfSense pfSense=2.7.0
pfSense pfSense Plus=23.05.01
Event History
Nov 14, 2023
CVE Published
12:00 AM
Data Sourced
12:00 AM
Description
Dec 12, 2023
News Published
02:00 PM
Frequently Asked Questions
1
What is the severity of CVE-2023-42327?
The severity of CVE-2023-42327 is medium with a CVSS score of 5.4.
2
How does the Cross Site Scripting (XSS) vulnerability in Netgate pfSense v.2.7.0 work?
The vulnerability allows a remote attacker to gain privileges by exploiting a crafted URL on the getserviceproviders.php page.
3
What is the affected software for CVE-2023-42327?
The affected software for CVE-2023-42327 is Netgate pfSense v.2.7.0.
4
How can I fix the Cross Site Scripting (XSS) vulnerability in Netgate pfSense v.2.7.0?
To fix the vulnerability, update to a version of Netgate pfSense that is not affected by the XSS vulnerability.
5
Where can I find more information about CVE-2023-42327?
More information about CVE-2023-42327 can be found at the following reference: https://docs.netgate.com/downloads/pfSense-SA-23_08.webgui.asc