Remote Code Execution Vulnerability in Netgate pfSense v.2.7.0 via Cross Site Scripting (XSS) in getserviceproviders.php

Remote Code Execution Vulnerability in Netgate pfSense v.2.7.0 via Cross Site Scripting (XSS) in getserviceproviders.php

CVE-2023-42327 · MEDIUM Severity

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

Cross Site Scripting (XSS) vulnerability in Netgate pfSense v.2.7.0 allows a remote attacker to gain privileges via a crafted URL to the getserviceproviders.php page.

Learn more about our Cis Benchmark Audit For Pfsense Firewall.