Vulnerability Description
OPNsense 19.1 contains a stored cross-site scripting vulnerability in the system_advanced_sysctl.php endpoint that allows attackers to inject persistent malicious scripts via the tunable parameter. Attackers can submit POST requests with script payloads that are stored and executed in the context of authenticated user sessions when the page is viewed.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Opnsense | Opnsense | 19.1 |
Related Weaknesses (CWE)
References
- https://forum.opnsense.org/index.php?topic=11469.0Release Notes
- https://opnsense.orgProduct
- https://www.exploit-db.com/exploits/46351ExploitThird Party AdvisoryVDB Entry
- https://www.vulncheck.com/advisories/opnsense-stored-xss-via-systemadvancedsysctBroken Link
FAQ
What is CVE-2019-25369?
CVE-2019-25369 is a vulnerability with a CVSS score of 6.4 (MEDIUM). OPNsense 19.1 contains a stored cross-site scripting vulnerability in the system_advanced_sysctl.php endpoint that allows attackers to inject persistent malicious scripts via the tunable parameter. At...
How severe is CVE-2019-25369?
CVE-2019-25369 has been rated MEDIUM with a CVSS base score of 6.4/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2019-25369?
Check the references section above for vendor advisories and patch information. Affected products include: Opnsense Opnsense.