CVE-2022-23993
26.01.2022, 19:15
/usr/local/www/pkg.php in pfSense CE before 2.6.0 and pfSense Plus before 22.01 uses $_REQUEST['pkg_filter'] in a PHP echo call, causing XSS.
Vendor | Product | Version |
---|---|---|
pfsense | pfsense | 𝑥 < 2.6.0 |
pfsense | pfsense_plus | 𝑥 < 22.01 |
𝑥
= Vulnerable software versions