CVE-2020-11457
pfSense before 2.4.5 has stored XSS in system_usermanager_addprivs.php in the WebGUI via the descr parameter (aka full n
pfSense before 2.4.5 has stored XSS in system_usermanager_addprivs.php in the WebGUI via the descr parameter (aka full name) of a user.
MEDIUM · CVSS 5.4
EPSS 0.05947
Schedule remediation
- EPSS percentile: top 9% of all CVEs by exploitation likelihood
- Public exploit or PoC is available
Sigma rules0
YARA rules0