CVE-2023-44276: XSS
Published Sep 28, 2023
·Updated
OPNsense before 23.7.5 allows XSS via the index.php sequence parameter to the Lobby Dashboard.
Affected Software
1 affected component
OPNsense OPNsense<23.7.5
Remediation
Event History
Sep 28, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Frequently Asked Questions
1
What is the vulnerability ID for this vulnerability?
The vulnerability ID for this vulnerability is CVE-2023-44276.
2
What is the severity of CVE-2023-44276?
The severity of CVE-2023-44276 is medium.
3
What is the affected software?
The affected software is Opnsense version up to exclusive 23.7.5.
4
How can the vulnerability be exploited?
The vulnerability can be exploited through a cross-site scripting (XSS) attack via the index.php sequence parameter to the Lobby Dashboard.
5
How can I fix CVE-2023-44276?
To fix CVE-2023-44276, you need to update Opnsense to version 23.7.5 or later.