Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-xq5r-rwpv-6jwc

Опубликовано: 15 фев. 2026
Источник: github
Github: Не прошло ревью
CVSS4: 5.1
CVSS3: 6.4

Описание

OPNsense 19.1 contains a stored cross-site scripting vulnerability that allows authenticated attackers to inject malicious scripts by submitting crafted input to the category parameter. Attackers can send POST requests to firewall_rules_edit.php with script payloads in the category field to execute arbitrary JavaScript in the browsers of other users accessing firewall rule pages.

OPNsense 19.1 contains a stored cross-site scripting vulnerability that allows authenticated attackers to inject malicious scripts by submitting crafted input to the category parameter. Attackers can send POST requests to firewall_rules_edit.php with script payloads in the category field to execute arbitrary JavaScript in the browsers of other users accessing firewall rule pages.

EPSS

Процентиль: 9%
0.00032
Низкий

5.1 Medium

CVSS4

6.4 Medium

CVSS3

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 6.4
nvd
около 2 месяцев назад

OPNsense 19.1 contains a stored cross-site scripting vulnerability that allows authenticated attackers to inject malicious scripts by submitting crafted input to the category parameter. Attackers can send POST requests to firewall_rules_edit.php with script payloads in the category field to execute arbitrary JavaScript in the browsers of other users accessing firewall rule pages.

EPSS

Процентиль: 9%
0.00032
Низкий

5.1 Medium

CVSS4

6.4 Medium

CVSS3

Дефекты

CWE-79