Vulnerabilities > Netgate > Pfsense Acme Package > Critical

DATE CVE VULNERABILITY TITLE RISK
2023-04-04 CVE-2020-21487 Cross-site Scripting vulnerability in Netgate Pfsense and Pfsense Acme Package
Cross Site Scripting vulnerability found in Netgate pfSense 2.4.4 and ACME package v.0.6.3 allows attackers to execute arbitrary code via the RootFolder field of acme_certificates.php.
network
low complexity
netgate CWE-79
critical
9.6