CVE-2020-19201

A Stored Cross-Site Scripting (XSS) vulnerability was found in status_filter_reload.php, a page in the pfSense software WebGUI, on Netgate pfSense version 2.4.4-p2 and earlier. The page did not encode output from the filter reload process, and a stored XSS was possible via the descr (description) parameter on NAT rules.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:netgate:pfsense:*:*:*:*:*:*:*:*
cpe:2.3:a:netgate:pfsense:2.4.4:p1:*:*:*:*:*:*
cpe:2.3:a:netgate:pfsense:2.4.4:p2:*:*:*:*:*:*

History

14 Sep 2021, 14:46

Type Values Removed Values Added
CPE cpe:2.3:a:pfsense:pfsense:2.4.4:p2:*:*:community:*:*:* cpe:2.3:a:netgate:pfsense:2.4.4:p1:*:*:*:*:*:*
cpe:2.3:a:netgate:pfsense:*:*:*:*:*:*:*:*
cpe:2.3:a:netgate:pfsense:2.4.4:p2:*:*:*:*:*:*
References
  • (MISC) https://gist.github.com/dharmeshbaskaran/fd3779006361d07651a883e8a040d916 - Exploit, Third Party Advisory

15 Jul 2021, 15:15

Type Values Removed Values Added
Summary Netgate pfSense 2.4.4 - p2 is affected by: Cross Site Scripting (XSS). The impact is: Authenticated Stored XSS in NAT Configuration (local). The component is: Description Text box, Status/Reload Filter Page. The attack vector is: An attacker get access to the victim's session by performing the CSRF and gather the cookie and session ids or possibly can change the victims NAT configuration using this Stored XSS. This attack can possibly spoof the victim's informations. A Stored Cross-Site Scripting (XSS) vulnerability was found in status_filter_reload.php, a page in the pfSense software WebGUI, on Netgate pfSense version 2.4.4-p2 and earlier. The page did not encode output from the filter reload process, and a stored XSS was possible via the descr (description) parameter on NAT rules.

14 Jul 2021, 12:54

Type Values Removed Values Added
References (MISC) https://www.pfsense.org/download/ - (MISC) https://www.pfsense.org/download/ - Vendor Advisory
References (MISC) https://docs.netgate.com/pfsense/en/latest/releases/2-4-4-p3.html - (MISC) https://docs.netgate.com/pfsense/en/latest/releases/2-4-4-p3.html - Product, Vendor Advisory
CPE cpe:2.3:a:pfsense:pfsense:2.4.4:p2:*:*:community:*:*:*
CWE CWE-79
CVSS v2 : unknown
v3 : unknown
v2 : 3.5
v3 : 5.4

12 Jul 2021, 16:19

Type Values Removed Values Added
New CVE

Information

Published : 2021-07-12 16:15

Updated : 2023-12-10 13:55


NVD link : CVE-2020-19201

Mitre link : CVE-2020-19201

CVE.ORG link : CVE-2020-19201


JSON object : View

Products Affected

netgate

  • pfsense
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')