Project

General

Profile

Actions

Bug #15778

open

Interface group members are not validated on load/save on ``interfaces_groups_edit.php``, and are printed without encoding on ``interfaces_groups.php``

Added by zhao mouren 16 days ago. Updated 14 days ago.

Status:
Feedback
Priority:
High
Assignee:
Category:
Interfaces
Target version:
Start date:
Due date:
% Done:

100%

Estimated time:
Plus Target Version:
24.11
Release Notes:
Default
Affected Version:
All
Affected Architecture:

Description

When submitting interface group members on interfaces_groups_edit.php the member list is not validated before it is then stored in the configuration. The group member list is then printed without encoding on interfaces_groups.php, leading to a potential stored XSS.

Original report URL: https://github.com/physicszq/web_issue/blob/main/pfsense/interfaces_groups_edit_file.md_xss.md

Actions

Also available in: Atom PDF