An XSS vulnerability resides in the hostname field of the diag_ping.php page in pfsense before 2.4.5 version. After passing inputs to the command and executing this command, the $result variable is not sanitized before it is printed.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: mitre
Published: 2020-04-29T13:29:52
Updated: 2024-08-04T11:14:15.605Z
Reserved: 2020-03-20T00:00:00
Link: CVE-2020-10797
Vulnrichment
No data.
NVD
Status : Modified
Published: 2020-04-29T14:15:16.967
Modified: 2024-11-21T04:56:05.610
Link: CVE-2020-10797
Redhat
No data.