CVE-2019-11816

Incorrect access control in the WebUI in OPNsense before version 19.1.8, and pfsense before 2.4.4-p3 allows remote authenticated users to escalate privileges to administrator via a specially crafted request.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:netgate:pfsense:*:*:*:*:*:*:*:*
cpe:2.3:a:netgate:pfsense:2.4.4:p1:*:*:*:*:*:*
cpe:2.3:a:netgate:pfsense:2.4.4:p2:*:*:*:*:*:*
cpe:2.3:a:opnsense:opnsense:*:*:*:*:*:*:*:*

History

21 Nov 2024, 04:21

Type Values Removed Values Added
References () https://forum.opnsense.org/index.php?topic=12787.0 - Release Notes, Vendor Advisory () https://forum.opnsense.org/index.php?topic=12787.0 - Release Notes, Vendor Advisory
References () https://www.netgate.com/blog/pfsense-2-4-4-release-p3-now-available.html - Release Notes, Vendor Advisory () https://www.netgate.com/blog/pfsense-2-4-4-release-p3-now-available.html - Release Notes, Vendor Advisory

Information

Published : 2019-05-20 22:29

Updated : 2024-11-21 04:21


NVD link : CVE-2019-11816

Mitre link : CVE-2019-11816

CVE.ORG link : CVE-2019-11816


JSON object : View

Products Affected

opnsense

  • opnsense

netgate

  • pfsense