MEDIUM
Multiple cross-site scripting (XSS) vulnerabilities in the Snort package before 3.0.13 for pfSense through 2.1.4 allow remote attackers to inject arbitrary web script or HTML via (1) the eng parameter to snort_import_aliases.php or (2) unspecified variables to snort_select_alias.php
Published Jul 2, 2014
4.3
MEDIUMCVSS 2.0
EPSS 1.66%
Description
Affected products
Remediation
Metrics
References (1)
Change history (0)
No recorded changes yet.