Loading
Cross-site scripting vulnerability in pfSense CE and pfSense Plus (pfSense CE software versions 2.5.2 and earlier, and pfSense Plus software versions 21.05 and earlier) allows a remote attacker to inject an arbitrary script via a malicious URL.
Use CWE-79, Netgate vendor hub and Pfsense Plus product page to widen CVE-2021-20729 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2023-27100, CVE-2024-54780 and CVE-2023-48123 for nearby disclosures in the same product family.