Shodan
Maps
Images
Monitor
Developer
More...
Dashboard
View Api Docs
Vulnerabilities
By Date
Known Exploited
Advanced Search
Vulnerable Software
Vendors
Products
Vulnerability Details CVE-2020-11457
pfSense before 2.4.5 has stored XSS in system_usermanager_addprivs.php in the WebGUI via the descr parameter (aka full name) of a user.
Exploit prediction scoring system (EPSS) score
EPSS Score
0.016
EPSS Ranking
80.6%
CVSS Severity
CVSS v3 Score
5.4
CVSS v2 Score
3.5
References
http://packetstormsecurity.com/files/157104/pfSense-2.4.4-P3-User-Manager-Cross-Site-Scripting.html
https://github.com/pfsense/pfsense/commit/3c1e53dabe966f27c9097a5a923e77f49ae5fffa
https://www.exploit-db.com/exploits/48300
https://www.netgate.com/assets/downloads/advisories/pfSense-SA-20_06.webgui.asc
http://packetstormsecurity.com/files/157104/pfSense-2.4.4-P3-User-Manager-Cross-Site-Scripting.html
https://github.com/pfsense/pfsense/commit/3c1e53dabe966f27c9097a5a923e77f49ae5fffa
https://www.exploit-db.com/exploits/48300
https://www.netgate.com/assets/downloads/advisories/pfSense-SA-20_06.webgui.asc
Products affected by CVE-2020-11457
Netgate
»
Pfsense
»
Version:
2.0
cpe:2.3:a:netgate:pfsense:2.0
Netgate
»
Pfsense
»
Version:
2.0.1
cpe:2.3:a:netgate:pfsense:2.0.1
Netgate
»
Pfsense
»
Version:
2.0.2
cpe:2.3:a:netgate:pfsense:2.0.2
Netgate
»
Pfsense
»
Version:
2.0.3
cpe:2.3:a:netgate:pfsense:2.0.3
Netgate
»
Pfsense
»
Version:
2.1.0
cpe:2.3:a:netgate:pfsense:2.1.0
Netgate
»
Pfsense
»
Version:
2.1.1
cpe:2.3:a:netgate:pfsense:2.1.1
Netgate
»
Pfsense
»
Version:
2.1.2
cpe:2.3:a:netgate:pfsense:2.1.2
Netgate
»
Pfsense
»
Version:
2.1.3
cpe:2.3:a:netgate:pfsense:2.1.3
Netgate
»
Pfsense
»
Version:
2.1.4
cpe:2.3:a:netgate:pfsense:2.1.4
Netgate
»
Pfsense
»
Version:
2.1.5
cpe:2.3:a:netgate:pfsense:2.1.5
Netgate
»
Pfsense
»
Version:
2.2
cpe:2.3:a:netgate:pfsense:2.2
Netgate
»
Pfsense
»
Version:
2.2.1
cpe:2.3:a:netgate:pfsense:2.2.1
Netgate
»
Pfsense
»
Version:
2.2.2
cpe:2.3:a:netgate:pfsense:2.2.2
Netgate
»
Pfsense
»
Version:
2.2.3
cpe:2.3:a:netgate:pfsense:2.2.3
Netgate
»
Pfsense
»
Version:
2.2.4
cpe:2.3:a:netgate:pfsense:2.2.4
Netgate
»
Pfsense
»
Version:
2.2.5
cpe:2.3:a:netgate:pfsense:2.2.5
Netgate
»
Pfsense
»
Version:
2.2.6
cpe:2.3:a:netgate:pfsense:2.2.6
Netgate
»
Pfsense
»
Version:
2.3
cpe:2.3:a:netgate:pfsense:2.3
Netgate
»
Pfsense
»
Version:
2.3.1
cpe:2.3:a:netgate:pfsense:2.3.1
Netgate
»
Pfsense
»
Version:
2.3.2
cpe:2.3:a:netgate:pfsense:2.3.2
Netgate
»
Pfsense
»
Version:
2.3.3
cpe:2.3:a:netgate:pfsense:2.3.3
Netgate
»
Pfsense
»
Version:
2.3.4
cpe:2.3:a:netgate:pfsense:2.3.4
Netgate
»
Pfsense
»
Version:
2.3.5
cpe:2.3:a:netgate:pfsense:2.3.5
Netgate
»
Pfsense
»
Version:
2.4
cpe:2.3:a:netgate:pfsense:2.4
Netgate
»
Pfsense
»
Version:
2.4.1
cpe:2.3:a:netgate:pfsense:2.4.1
Netgate
»
Pfsense
»
Version:
2.4.2
cpe:2.3:a:netgate:pfsense:2.4.2
Netgate
»
Pfsense
»
Version:
2.4.3
cpe:2.3:a:netgate:pfsense:2.4.3
Netgate
»
Pfsense
»
Version:
2.4.4
cpe:2.3:a:netgate:pfsense:2.4.4
Products
Monitor
Search Engine
Developer API
Maps
Bulk Data
Images
Snippets
Pricing
Membership
API Subscriptions
Enterprise
Contact Us
support@shodan.io
Shodan ® - All rights reserved