An XSS issue was discovered in pfSense through 2.4.4-p3. In services_captiveportal_mac.php, the username and delmac parameters are displayed without sanitization.
2019-09-26T18:15:10.743
2024-11-21T04:31:20.003
Modified
CVSSv3.1: 6.1 (MEDIUM)
AV:N/AC:M/Au:N/C:N/I:P/A:N
8.6
2.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | netgate | pfsense | < 2.4.4 | Yes |
Application | netgate | pfsense | 2.4.4 | Yes |
Application | netgate | pfsense | 2.4.4 | Yes |
Application | netgate | pfsense | 2.4.4 | Yes |
Application | netgate | pfsense | 2.4.4 | Yes |