diag_command.php in pfSense 2.4.4-p3 allows CSRF via the txtCommand or txtRecallBuffer field, as demonstrated by executing OS commands. This occurs because csrf_callback() produces a "CSRF token expired" error and a Try Again button when a CSRF token is missing.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2019-09-26T18:38:48

Updated: 2024-08-05T01:17:41.055Z

Reserved: 2019-09-21T00:00:00

Link: CVE-2019-16667

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2019-09-26T19:15:12.447

Modified: 2020-07-27T21:15:13.487

Link: CVE-2019-16667

cve-icon Redhat

No data.