CVE detail
CVE-2019-18667 — CVE-2019-18667
Published 2019-11-02 · Modified 2026-06-17 · Vendor pfsense · Product pfsense-pkg-freeradius3 · Source nvd
MEDIUM
severity
CVSS-derived band
0.0400
EPSS probability
exploitation probability, 30d
90.0%
EPSS percentile
percentile vs all CVEs
NOT LISTED
CISA KEV
known exploited catalog
Description
/usr/local/www/freeradius_view_config.php in the freeradius3 package before 0.15.7_3 for pfSense on FreeBSD allows a user with an XSS payload as password or username to execute arbitrary javascript code on a victim browser.
Remediation
No vendor-published fix data in our corpus for this CVE. Check the references below or the vendor's PSIRT / security advisories page.
References