Cross-site request forgery (CSRF) vulnerability in systemfirmwarerestorefullbackup.php in the WebGUI in pfSense before 2.2.1 allows remote attackers to hijack the authentication of administrators for requests that delete arbitrary files via the deletefile parameter.
Multiple cross-site scripting (XSS) vulnerabilities in the WebGUI in pfSense before 2.2.1 allow remote attackers to inject arbitrary web script or HTML via the (1) zone parameter to statuscaptiveportal.php; (2) if or (3) dragtable parameter to firewallrules.php; (4) queue parameter in an add action to firewallshaper.php; (5) id parameter in an edit action to servicesunboundacls.php; or (6) filterlogentriestime, (7) filterlogentriessourceipaddress, (8) filterlogentriessourceport, (9) filterlogentriesdestinationipaddress, (10) filterlogentriesinterfaces, (11) filterlogentriesdestinationport, (12) filterlogentriesprotocolflags, or (13) filterlogentriesqty parameter to diaglogsfilter.php.