CVE-2019-8953 – pfSense 2.4.4-p1 (HAProxy Package 0.59_14) - Persistent Cross-Site Scripting
https://notcve.org/view.php?id=CVE-2019-8953
The HAProxy package before 0.59_16 for pfSense has XSS via the desc (aka Description) or table_actionsaclN parameter, related to haproxy_listeners.php and haproxy_listeners_edit.php. El paquete HAProxy, en versiones anteriores a la 0.59_16 para pfSense, tiene Cross-Site Scripting (XSS) mediante los parámetros desc (también conocido como Description) o table_actionsaclN, relacionados con haproxy_listeners.php y haproxy_listeners_edit.php. pfSense version 2.4.4-p1 with HAProxy Package version 0.59_14 suffers from a cross site scripting vulnerability. • https://www.exploit-db.com/exploits/46538 https://cxsecurity.com/issue/WLB-2019020153 https://github.com/pfsense/FreeBSD-ports/commit/2dded47b3202dfdf89aa96f84bf701b3d5acbe6c https://github.com/pfsense/FreeBSD-ports/commit/3b40366aca55910b224ecf49d3fdacc9ad6c04f5 https://redmine.pfsense.org/issues/9335 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •