Cross Site Scripting vulnerability found in Netgate pfSense 2.4.4 and ACME package v.0.6.3 allows attackers to execute arbitrary code via the RootFolder field of acme_certificates.php.
2023-04-04T15:15:08.147
2025-02-13T17:15:25.783
Modified
CVSSv3.1: 9.6 (CRITICAL)
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | netgate | pfsense | 2.4.4 | Yes |
Application | netgate | pfsense_acme_package | 0.6.3 | Yes |