CVE-2023-27253

pfsense/pfsense
on GitHub

Published

Mar 17, 2023

Severity

CVSS v3:
N/A
CVSS v2:
N/A

Description

A command injection vulnerability in the function restore_rrddata() of Netgate pfSense v2.7.0 allows authenticated attackers to execute arbitrary commands via manipulating the contents of an XML file supplied to the component config.xml.

References

Configurations

CPE23 Version Start Version End Exact Version

External Links