CVE-2019-16667
26.09.2019, 19:15
diag_command.php in pfSense 2.4.4-p3 allows CSRF via the txtCommand or txtRecallBuffer field, as demonstrated by executing OS commands. This occurs because csrf_callback() produces a "CSRF token expired" error and a Try Again button when a CSRF token is missing.
Vendor | Product | Version |
---|---|---|
netgate | pfsense | 2.4.4:p3 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration