An XSS vulnerability resides in the hostname field of the diag_ping.php page in pfsense before 2.4.5 version. After passing inputs to the command and executing this command, the $result variable is not sanitized before it is printed.
Metrics
Affected Vendors & Products
References
History
No history.

Status: PUBLISHED
Assigner: mitre
Published: 2020-04-29T13:29:52
Updated: 2024-08-04T11:14:15.605Z
Reserved: 2020-03-20T00:00:00
Link: CVE-2020-10797

No data.

Status : Modified
Published: 2020-04-29T14:15:16.967
Modified: 2024-11-21T04:56:05.610
Link: CVE-2020-10797

No data.