CVE-2019-25369
MEDIUMOPNsense 19.1 - Stored Cross-Site Scripting via System Advanced Sysctl Tunable Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2019-25369. PoCs published by Ozer Goker.
AI-analyzed exploit summary This exploit demonstrates multiple reflected and stored XSS vulnerabilities in OPNsense 19.1. It provides specific URLs, methods, parameters, and payloads for each XSS vector.
Description
OPNsense 19.1 contains a stored cross-site scripting vulnerability in the system_advanced_sysctl.php endpoint that allows attackers to inject persistent malicious scripts via the tunable parameter. Attackers can submit POST requests with script payloads that are stored and executed in the context of authenticated user sessions when the page is viewed.
Exploits (1)
This exploit demonstrates multiple reflected and stored XSS vulnerabilities in OPNsense 19.1. It provides specific URLs, methods, parameters, and payloads for each XSS vector.
References (4)
Scores
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N