CVE-2023-44275: XSS
OPNsense before 23.7.5 allows XSS via the index.php columncount parameter to the Lobby Dashboard.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2023-44275?
CVE-2023-44275 is a vulnerability in OPNsense before 23.7.5 that allows XSS attacks via the index.php column_count parameter to the Lobby Dashboard.
How severe is CVE-2023-44275?
CVE-2023-44275 has a severity score of 5.4, which is considered medium.
Which software versions are affected by CVE-2023-44275?
OPNsense versions up to exclusive 23.7.5 are affected by CVE-2023-44275.
How can I fix CVE-2023-44275?
To fix CVE-2023-44275, update OPNsense to version 23.7.5 or later.
Where can I find more information about CVE-2023-44275?
More information about CVE-2023-44275 can be found at the following references: [GitHub commit](https://github.com/opnsense/core/commit/484753b2abe3fd0fcdb73d8bf00c3fc3709eb8b7), [GitHub comparison](https://github.com/opnsense/core/compare/23.7.4...23.7.5), [X41-DSEC advisory](https://www.x41-dsec.de/lab/advisories/x41-2023-001-opnsense).