CVE-2024-46538
MEDIUMpfSense 2.5.2 - Stored Cross-Site Scripting via $pconfig Variable in interfaces_groups_edit.php
Title source: llmExploitation Summary
EIP tracks 2 public exploits for CVE-2024-46538. PoCs published by EQSTLab, LauLeysen.
AI-analyzed exploit summary This is a Python-based exploit for CVE-2024-46538, a stored XSS vulnerability in pfSense 2.5.2. It automates the process of injecting a malicious JavaScript payload via the interfaces_groups_edit.php page, which then executes arbitrary commands via a CSRF-protected endpoint.
Description
A cross-site scripting (XSS) vulnerability in pfsense v2.5.2 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the $pconfig variable at interfaces_groups_edit.php.
Exploits (2)
This is a Python-based exploit for CVE-2024-46538, a stored XSS vulnerability in pfSense 2.5.2. It automates the process of injecting a malicious JavaScript payload via the interfaces_groups_edit.php page, which then executes arbitrary commands via a CSRF-protected endpoint.
This is a Python-based exploit for CVE-2024-46538, a stored XSS vulnerability in pfSense v2.5.2. It leverages a crafted payload to execute arbitrary JavaScript, which then performs command execution and user creation via CSRF token manipulation.
References (2)
Scores
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N