Vulnerability Name: | CVE-2022-42247 (CCN-237784) | ||||||||||||
Assigned: | 2022-10-02 | ||||||||||||
Published: | 2022-10-02 | ||||||||||||
Updated: | 2022-10-05 | ||||||||||||
Summary: | pfSense v2.5.2 was discovered to contain a cross-site scripting (XSS) vulnerability in the browser.php component. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into a file name. | ||||||||||||
CVSS v3 Severity: | 6.1 Medium (CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N) 5.8 Medium (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N/E:H/RL:O/RC:C)
6.9 Medium (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N/E:H/RL:O/RC:C)
| ||||||||||||
CVSS v2 Severity: | 6.4 Medium (CCN CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:P/A:N)
| ||||||||||||
Vulnerability Type: | CWE-79 | ||||||||||||
Vulnerability Consequences: | Cross-Site Scripting | ||||||||||||
References: | Source: MITRE Type: CNA CVE-2022-42247 Source: XF Type: UNKNOWN pfsense-cve202242247-xss(237784) Source: CCN Type: GitHub Web site XSS vulnerability in pfsense v2.5.2 Source: MISC Type: Exploit, Patch, Third Party Advisory https://gist.github.com/enferas/b4ca7a4fb52e1b5e698f87e4d655a70a Source: CCN Type: pfSense GIT Repository Encode path+fn in browser.php. Fixes #13262 Source: MISC Type: Patch, Third Party Advisory https://github.com/pfsense/pfsense/commit/73ca6743954ac9f35ca293e3f2af63eac20cf32e Source: CCN Type: Mend Vulnerability Database CVE-2022-42247 Source: CCN Type: pfSense Web site pfSense | ||||||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: ![]() | ||||||||||||
BACK |