CVE-2019-25368
MEDIUMOPNsense 19.1 - Cross-Site Scripting via diag_backup.php Parameters
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2019-25368. PoCs published by Ozer Goker.
AI-analyzed exploit summary This exploit demonstrates multiple reflected and stored XSS vulnerabilities in OPNsense 19.1. It provides specific URLs, methods, parameters, and payloads for each XSS vector.
Description
OPNsense 19.1 contains multiple cross-site scripting vulnerabilities in the diag_backup.php endpoint that allow attackers to inject malicious scripts through multiple parameters including GDrive_GDriveEmail, GDrive_GDriveFolderID, GDrive_GDriveBackupCount, Nextcloud_url, Nextcloud_user, Nextcloud_password, Nextcloud_password_encryption, and Nextcloud_backupdir. Attackers can submit POST requests with script payloads in these parameters to execute arbitrary JavaScript in the context of authenticated administrator sessions.
Exploits (1)
This exploit demonstrates multiple reflected and stored XSS vulnerabilities in OPNsense 19.1. It provides specific URLs, methods, parameters, and payloads for each XSS vector.
References (4)
Scores
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N