Loading
An XSS vulnerability resides in the hostname field of the diag_ping.php page in pfsense before 2.4.5 version. After passing inputs to the command and executing this command, the $result variable is not sanitized before it is printed.
Use CWE-79, Netgate vendor hub and Pfsense product page to widen CVE-2020-10797 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2020-21487, CVE-2023-48123 and CVE-2023-42326 for nearby disclosures in the same product family.