Описание
In pfSense CE /suricata/suricata_app_parsers.php, the value of the policy_name parameter is not sanitized of HTML-related strings/characters before being directly displayed. This can result in stored cross-site scripting. The attacker must be authenticated with at least "WebCfg - Services: suricata package" permissions.
Уязвимые конфигурации
Конфигурация 1Версия до 2.8.0 (исключая)
cpe:2.3:a:pfsense:pfsense:*:*:*:*:community:*:*:*
EPSS
Процентиль: 3%
0.00016
Низкий
5.4 Medium
CVSS3
Дефекты
CWE-79
Связанные уязвимости
CVSS3: 5.4
github
5 месяцев назад
In pfSense CE /suricata/suricata_app_parsers.php, the value of the policy_name parameter is not sanitized of HTML-related strings/characters before being directly displayed. This can result in stored cross-site scripting. The attacker must be authenticated with at least "WebCfg - Services: suricata package" permissions.
EPSS
Процентиль: 3%
0.00016
Низкий
5.4 Medium
CVSS3
Дефекты
CWE-79