NA

CVE-2020-21487

Published: 04/04/2023 Updated: 10/04/2023
CVSS v3 Base Score: 9.6 | Impact Score: 6 | Exploitability Score: 2.8
VMScore: 0

Vulnerability Summary

Cross Site Scripting vulnerability found in Netgate pfSense 2.4.4 and ACME package v.0.6.3 allows malicious users to execute arbitrary code via the RootFolder field of acme_certificates.php.

Vulnerable Product Search on Vulmon Subscribe to Product

netgate pfsense 2.4.4

netgate pfsense acme package 0.6.3