Vulnerability Description
/usr/local/www/freeradius_view_config.php in the freeradius3 package before 0.15.7_3 for pfSense on FreeBSD allows a user with an XSS payload as password or username to execute arbitrary javascript code on a victim browser.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Pfsense | Pfsense-Pkg-Freeradius3 | < 0.15.7_3 |
Related Weaknesses (CWE)
References
- https://github.com/pfsense/FreeBSD-ports/commit/30b22b6b0db7b73732a5da346afca66dPatchThird Party Advisory
- https://github.com/pfsense/FreeBSD-ports/commit/30b22b6b0db7b73732a5da346afca66dPatchThird Party Advisory
FAQ
What is CVE-2019-18667?
CVE-2019-18667 is a vulnerability with a CVSS score of 6.1 (MEDIUM). /usr/local/www/freeradius_view_config.php in the freeradius3 package before 0.15.7_3 for pfSense on FreeBSD allows a user with an XSS payload as password or username to execute arbitrary javascript co...
How severe is CVE-2019-18667?
CVE-2019-18667 has been rated MEDIUM with a CVSS base score of 6.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2019-18667?
Check the references section above for vendor advisories and patch information. Affected products include: Pfsense Pfsense-Pkg-Freeradius3.