4.3
CVSSv2

CVE-2019-12949

Published: 25/06/2019 Updated: 25/06/2019
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
CVSS v3 Base Score: 6.1 | Impact Score: 2.7 | Exploitability Score: 2.8
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

In pfSense 2.4.4-p2 and 2.4.4-p3, if it is possible to trick an authenticated administrator into clicking on a button on a phishing page, an attacker can leverage XSS to upload arbitrary executable code, via diag_command.php and rrd_fetch_json.php (timePeriod parameter), to a server. Then, the remote attacker can run any command with root privileges on that server.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

netgate pfsense 2.4.4

Github Repositories

CVE-2019-12949

[CVE-2019-12949] From Cross Site Scripting Vulnerability to Remote Code Execution in pfSense 244-p2 and 244-p3 Information Description: In pfSense 244-p2 and 244-p3, if it is possible to trich the authenticated administrator into clicking on a button on a phishing page, an attacker can upload arbitrary executable code via ding_commandphp and rrd_fetch_jsonphp, to a se