S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
medium·Product Based Web Vulnerabilities·Updated Mar 9, 2024

CVE-2023-39002 Scanner

CVE-2023-39002 scanner - Cross-Site Scripting vulnerability in OPNsense

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, ipv4, subdomain
CostFree
2.6k
Times Used
continuous scan runs
5.9k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
6.1
CVSS
Description

A cross-site scripting (XSS) vulnerability in the act parameter of system_certmanager.php in OPNsense Community Edition before 23.7 and Business Edition before 23.4.2 allows attackers to execute arbitrary web scripts or HTML via a crafted payload.

Attack Vector
-
Privileges Req.
-
User Interaction
-
Affected
n/aby n/a
n/a
Updated Sep 18, 2026View on NVD →
Detail

OPNsense is a robust, open-source firewall and routing platform based on FreeBSD. It's widely utilized by network administrators and IT professionals to secure network infrastructures. OPNsense includes features like traffic shaping, load balancing, and a virtual private network, making it a comprehensive solution for network security. It's developed with a focus on security, reliability, and user-friendliness, providing a powerful tool for managing network traffic and protecting against cyber threats.

The vulnerability CVE-2023-39002 is a Cross-Site Scripting (XSS) issue found in OPNsense versions before 23.7. It exists in the system_certmanager.php file, specifically in the act parameter, where malicious scripts can be injected. This vulnerability allows attackers to execute arbitrary web scripts or HTML, leading to potential theft of cookies, session tokens, or sensitive information presented in the browser. It requires user interaction, as the malicious script needs to be triggered by the user, making it a reflected XSS attack.

The flaw is due to improper sanitization of the input passed through the act parameter to the system_certmanager.php file. By embedding a crafted payload in the URL, an attacker can inject a malicious script into the webpage rendered by the victim's browser. The script then executes within the context of the user's session with the application. This vulnerability highlights a common web application security oversight, emphasizing the need for strict input validation and encoding practices.

If exploited, this XSS vulnerability can lead to various security issues, including session hijacking, redirection to phishing sites, and the execution of unauthorized actions on behalf of the user. It compromises the integrity and confidentiality of user sessions and can erode trust in the security of the OPNsense platform. In a worst-case scenario, it could lead to the compromise of administrator accounts, giving attackers potential control over the firewall and routing settings.

Joining the S4E platform provides access to advanced scanning capabilities and expert guidance to identify vulnerabilities like CVE-2023-39002 in OPNsense. Our service enables users to proactively detect and address security issues, enhancing the protection of network infrastructures against emerging threats. Membership on our platform ensures continuous monitoring and reporting on potential vulnerabilities, helping maintain a strong security posture for your digital assets.

 

References

Solution Advice
  1. Update OPNsense to version 23.7 or later, which contains patches for this vulnerability.
  2. Implement content security policies that prevent the execution of unauthorized scripts.
  3. Regularly review and sanitize all user inputs to ensure that they are properly encoded before being rendered on the page.
  4. Conduct periodic security assessments and penetration testing to identify and mitigate vulnerabilities in the system.
  5. Train administrators and users on the importance of cybersecurity hygiene, including recognizing and avoiding phishing attempts that could exploit such vulnerabilities.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

CVE-2023-39002 scanner - Cross-Site Scripting vulnerability in OPNsense | S4E