CVE-2020-21487

Published
View on NVD ↗
CVSS v3
9.6
CRITICAL
CVSS v2
N/A
Affected
1
PROJECT

Description

Cross Site Scripting vulnerability found in Netgate pfSense 2.4.4 and ACME package v.0.6.3 allows attackers to execute arbitrary code via the RootFolder field of acme_certificates.php.

FreeBSD ports tree with pfSense changes
GitHubGitHub
515