Back to search
CVE-2019-12347
Published: May 29, 2019
Modified: Aug 4, 2024
PUBLISHED
Description
In pfSense 2.4.4-p3, a stored XSS vulnerability occurs when attackers inject a payload into the Name or Description field via an acme_accountkeys_edit.php action. The vulnerability occurs due to input validation errors.
| Vendor | Product | Versions |
|---|---|---|
n/a | n/a | affected n/a |
References
https://redmine.pfsense.org/issues/9554#change-40729
x_refsource_MISC
https://www.pfsense.org/download/
x_refsource_MISC
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now