Netgate.pfSense.haproxy_listeners_edit.php.Stored.XSS

description-logoDescription

This indicates an attack attempt to exploit a Cross Site Scripting Vulnerability in Netgate pfSense.
A remote, authenticated attacker could exploit this vulnerability by sending crafted HTTP requests to the target system. Successful exploitation could result in the execution of arbitrary JavaScript code by the browsers of other pfSense users.

affected-products-logoAffected Products

The HAProxy package before 0.59_16

Impact logoImpact

System Compromise: Remote attackers can gain control of vulnerable systems.

recomended-action-logoRecommended Actions

Apply the most recent upgrade or patch from the vendor.
https://redmine.pfsense.org/issues/9335

Telemetry logoTelemetry

Coverage

IPS (Regular DB)
IPS (Extended DB)

Version Updates

Date Version Detail
2019-07-11 14.647 Default_action:pass:drop
2019-07-03 14.642