diag_command.php in pfSense 2.4.4-p3 allows CSRF via the txtCommand or txtRecallBuffer field, as demonstrated by executing OS commands. This occurs because csrf_callback() produces a "CSRF token expired" error and a Try Again button when a CSRF token is missing.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: mitre
Published: 2019-09-26T18:38:48
Updated: 2024-08-05T01:17:41.055Z
Reserved: 2019-09-21T00:00:00
Link: CVE-2019-16667
Vulnrichment
No data.
NVD
Status : Modified
Published: 2019-09-26T19:15:12.447
Modified: 2024-11-21T04:30:56.187
Link: CVE-2019-16667
Redhat
No data.