CVE-2015-2295
10.04.2015, 15:00
Cross-site request forgery (CSRF) vulnerability in system_firmware_restorefullbackup.php in the WebGUI in pfSense before 2.2.1 allows remote attackers to hijack the authentication of administrators for requests that delete arbitrary files via the deletefile parameter.
Vendor | Product | Version |
---|---|---|
netgate | pfsense | 𝑥 ≤ 2.2 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
References