Arbitrary Code Execution via Cross Site Scripting in Netgate pfSense 2.4.4 and ACME Package v.0.6.3

Arbitrary Code Execution via Cross Site Scripting in Netgate pfSense 2.4.4 and ACME Package v.0.6.3

CVE-2020-21487 · CRITICAL Severity

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H

Cross Site Scripting vulnerability found in Netgate pfSense 2.4.4 and ACME package v.0.6.3 allows attackers to execute arbitrary code via the RootFolder field of acme_certificates.php.

Learn more about our Cis Benchmark Audit For Pfsense Firewall.