Cross-site scripting vulnerability in pfSense CE and pfSense Plus (pfSense CE software versions 2.5.2 and earlier, and pfSense Plus software versions 21.05 and earlier) allows a remote attacker to inject an arbitrary script via a malicious URL.
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
Link | Tags |
---|---|
https://docs.netgate.com/downloads/pfSense-SA-21_02.captiveportal.asc | third party advisory |
https://jvn.jp/en/jp/JVN87751554/index.html | third party advisory vdb entry |