TGViewer
Netlas.io Netlas.io @netlas · 2.33K subscribers
Post #127 3.06K
CVE-2023-42325, -42326, -42327: XSS and RCE in pfSense Security, 5.4 - 8.8 rating 🔥

By combining vulnerabilities, an attacker can force a user to activate XSS payload and thereby achieve RCE. pfSense CE 2.7.0 and below, pfSense Plus 23.05.1 and below are vulnerable.

Search at
Netlas.io:
👉
Link (tag, more results): https://nt.ls/BRDDo
👉 Link (no tag): https://nt.ls/Mr8WD
👉 Dork: http.favicon.hash_sha256:b2dd935235013a51fde0a2afc12ba965952e384b7ab43fe1746cc21c7eafc38c

Vendor's advisory:
https://docs.netgate.com/downloads/pfSense-SA-23_08.webgui.asc
  • 👾 6
  • 👍 1
More from @netlas
  1. Oct 5, 2026CVE-2026-96940: EoP vulnerability in MS Exchange Server, 8.8 rating ‍🔥 Microsoft has upda…
  2. Oct 2, 2026CVE-2026-63292 and others: Multiple vulnerabilities in Apache HTTP Server, up to 9.8 ratin…
  3. Sep 29, 2026CVE-2026-88771 & CVE-2026-88772: RCE and/or DoS in Citrix NetScaler ADC and NetScaler Gate…
  4. Sep 25, 2026CVE-2026-13016 and others: Multiple vulnerabilities in ServiceNow, up to 9.3 Rating 🔥 Rec…
  5. Sep 24, 2026CVE-2026-88804: Unauthenticated update of public UI settings leading to stored XSS in Ranc…
  6. Sep 23, 2026CVE-2026-87902: Path Traversal in WordPress leading to RCE, 9.2 Rating 🔥 Another newly di…
Threads Profile ViewerView any public Threads profile without an account.Open ThreadLook →Writing with AI? Make it sound human.Metric37 rewrites AI drafts so they read naturally. Free AI detector, 1,500 words free.Try Metric37 →