VulnerabilityModified
CVE-2022-29273
pfSense CE through 2.6.0 and pfSense Plus before 22.05 allow XSS in the WebGUI via URL Table Alias URL parameters.
MEDIUM 6.1EPSS 59.6%
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 59.6%, higher than 99% of all known CVEs. Patch or mitigate before the next change window.
Description
pfSense CE through 2.6.0 and pfSense Plus before 22.05 allow XSS in the WebGUI via URL Table Alias URL parameters.
- CVSS 3.1
- 6.1 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
- EPSS
- 59.56% probability · 99th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-79
- Affected
- netgate/pfsense
- Source
- cve@mitre.org
References
- https://docs.netgate.com/downloads/pfSense-SA-22_05.webgui.asc
- https://docs.netgate.com/pfsense/en/latest/releases/index.html#current-and-upcoming-supported-releasesRelease Notes
- https://redmine.pfsense.org/issues/13060Patch
- https://docs.netgate.com/downloads/pfSense-SA-22_05.webgui.asc
- https://docs.netgate.com/pfsense/en/latest/releases/index.html#current-and-upcoming-supported-releasesRelease Notes
- https://redmine.pfsense.org/issues/13060Patch
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.