A cross-site scripting (XSS) vulnerability in the act parameter of system_certmanager.php in OPNsense Community Edition before 23.7 and Business Edition before 23.4.2 allows attackers to execute arbitrary web scripts or HTML via a crafted payload.
Tracking
Sign in to view the affected projects.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Thu, 10 Oct 2024 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-10-10T15:33:42.861Z
Reserved: 2023-07-25T00:00:00.000Z
Link: CVE-2023-39002
Updated: 2024-08-02T17:54:39.987Z
Status : Modified
Published: 2023-08-09T19:15:14.900
Modified: 2024-11-21T08:14:36.020
Link: CVE-2023-39002
No data.
OpenCVE Enrichment
No data.
Weaknesses