packetstormsecurity.com
http://packetstormsecurity.com/files/158614/pfSense-2.4.4-p3-Cross-Site-Request-Forgery.html CVE-2019-16667
HIGH
pfSense 2.4.4-p3 - Cross-Site Request Forgery
Record summary
CVE-2019-16667 has a selected CVSS score of 8.8 (high); EIP currently links 1 catalogued exploit.
Description
diag_command.php in pfSense 2.4.4-p3 allows CSRF via the txtCommand or txtRecallBuffer field, as demonstrated by executing OS commands. This occurs because csrf_callback() produces a "CSRF token expired" error and a Try Again button when a CSRF token is missing.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBpfSense 2.4.4-p3 - Cross-Site Request ForgeryExploitDB exploitby ghost_fhNot analyzed1 file
References
3nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2019-16667 pastebin.com
https://pastebin.com/TEJdu9LN