Sploitus

CVE-2020-11457

3 known exploits for CVE-2020-11457

pfSense before 2.4.5 has stored XSS in system_usermanager_addprivs.php in the WebGUI via the descr parameter (aka full name) of a user.

Affected products
Pfsense
Netgate Pfsense
< 2.4.5
Fix
Available
CVSS 3.1
5.4 MEDIUM
EPSS
9.3% (95th percentile)
Weakness
CWE-79
NVD status
Modified
Published
2020-04-01
CVE-2020-11457 at NVD
Authoritative description, scoring and affected products

3 known exploits for CVE-2020-11457

Proof-of-concept code and exploit modules indexed by Sploitus