Known CVE
OPNsense - Cross-Site Scripting to RCE
There is a XSS in /ui/cron/item/open in the Cron component of OPNsense Community Edition before 23.7 and Business Edition before 23.4.2 via openAction in app/controllers/OPNsense/Cron/ItemController.php.
CVE-2023-39007
Critical2023CVSS 9.6CWE-79
cve2023 · opnsense · xss · authenticated · rce · vuln
Verified scans run this check after you prove you own the site.
All known CVEsView the checks catalogNational Vulnerability Database
Scan a website