CVE-2019-12584

Apcupsd 0.3.91_5, as used in pfSense through 2.4.4-RELEASE-p3 and other products, has an XSS issue in apcupsd_status.php.
Configurations

Configuration 1 (hide)

cpe:2.3:a:apcupsd:apcupsd:0.3.91_5:*:*:*:*:*:*:*

Configuration 2 (hide)

OR cpe:2.3:a:netgate:pfsense:*:*:*:*:*:*:*:*
cpe:2.3:a:netgate:pfsense:2.4.4:-:*:*:*:*:*:*
cpe:2.3:a:netgate:pfsense:2.4.4:p1:*:*:*:*:*:*
cpe:2.3:a:netgate:pfsense:2.4.4:p2:*:*:*:*:*:*
cpe:2.3:a:netgate:pfsense:2.4.4:p3:*:*:*:*:*:*

History

21 Nov 2024, 04:23

Type Values Removed Values Added
References () https://ctrsec.io/index.php/2019/05/28/cve-2019-12584-12585-command-injection-vulnerability-on-pfsense-2-4-4-release-p3/ - () https://ctrsec.io/index.php/2019/05/28/cve-2019-12584-12585-command-injection-vulnerability-on-pfsense-2-4-4-release-p3/ -
References () https://github.com/pfsense/FreeBSD-ports/commit/b492c0ea47aba8dde2f14183e71498ba207594e3 - Patch, Third Party Advisory () https://github.com/pfsense/FreeBSD-ports/commit/b492c0ea47aba8dde2f14183e71498ba207594e3 - Patch, Third Party Advisory
References () https://redmine.pfsense.org/issues/9556 - Third Party Advisory () https://redmine.pfsense.org/issues/9556 - Third Party Advisory

Information

Published : 2019-06-03 03:29

Updated : 2024-11-21 04:23


NVD link : CVE-2019-12584

Mitre link : CVE-2019-12584

CVE.ORG link : CVE-2019-12584


JSON object : View

Products Affected

apcupsd

  • apcupsd

netgate

  • pfsense
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')