CVE-2022-23993

/usr/local/www/pkg.php in pfSense CE before 2.6.0 and pfSense Plus before 22.01 uses $_REQUEST['pkg_filter'] in a PHP echo call, causing XSS.
Configurations

Configuration 1

cpe:2.3:a:pfsense:pfsense_plus:*:*:*:*:*:*:*:*
cpe:2.3:a:pfsense:pfsense:*:*:*:*:*:*:*:*

Information

Published : 2022-01-26 07:15

Updated : 2022-04-29 07:32


NVD link : CVE-2022-23993

Mitre link : CVE-2022-23993

Products Affected
No products.
CWE