CVE Published: 31/03/2022 |
CVE Updated: 03/08/2024 |
CVE Year: 2021 Source: jpcert |
Vendor: pfSense |
Product: pfSense CE and pfSense Plus Status : PUBLISHED
CVE-2021-20729 Description
Cross-site scripting vulnerability in pfSense CE and pfSense Plus (pfSense CE software versions 2.5.2 and earlier, and pfSense Plus software versions 21.05 and earlier) allows a remote attacker to inject an arbitrary script via a malicious URL.