PT-2026-85052 · Netgate · Pfsense Ce+1

·

CVE-2026-56127

·

Publicado

2026-09-03

·

Atualizado

2026-09-03

CVSS v3.1

5.4

Média

VetorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
pfSense Plus before 26.07 and CE before 2.9.0 allow authenticated users with the Firewall: Rules: Edit privilege to inject arbitrary JavaScript via the descr parameter in /firewall rules edit.php. The firewall rule description is stored in the pfSense XML configuration with only backslash-escaping applied and no HTML sanitization, then rendered without encoding in the firewall log table in /status logs filter.php. The payload executes in the browser of any user with the Status: Logs: Firewall privilege who views the affected log entries.

Correção

XSS

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2026-56127

Produtos afetados

Pfsense Ce
Pfsense Plus