First published: Tue Nov 14 2023(Updated: )
Cross Site Scripting (XSS) vulnerability in Netgate pfSense v.2.7.0 allows a remote attacker to gain privileges via a crafted URL to the getserviceproviders.php page.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Netgate pfSense | =2.7.0 | |
pfSense pfSense | =2.7.0 | |
pfSense pfSense Plus | =23.05.01 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2023-42327 is medium with a CVSS score of 5.4.
The vulnerability allows a remote attacker to gain privileges by exploiting a crafted URL on the getserviceproviders.php page.
The affected software for CVE-2023-42327 is Netgate pfSense v.2.7.0.
To fix the vulnerability, update to a version of Netgate pfSense that is not affected by the XSS vulnerability.
More information about CVE-2023-42327 can be found at the following reference: https://docs.netgate.com/downloads/pfSense-SA-23_08.webgui.asc