NA

CVE-2023-38997

Published: 09/08/2023 Updated: 22/02/2024
CVSS v3 Base Score: 7.2 | Impact Score: 5.9 | Exploitability Score: 1.2
VMScore: 0

Vulnerability Summary

A directory traversal vulnerability in the Captive Portal templates of OPNsense Community Edition prior to 23.7 and Business Edition prior to 23.4.2 allows malicious users to execute arbitrary system commands as root via a crafted ZIP archive.

Vulnerable Product Search on Vulmon Subscribe to Product

opnsense opnsense