← Back to CVE List

CVE-2019-16667

Published: 2019-09-26T19:15Z
Last Modified: 2024-11-21T04:30Z
Source: MITRE CVE List
License: MITRE-CVE-TOS
diag_command.php in pfSense 2.4.4-p3 allows CSRF via the txtCommand or txtRecallBuffer field, as demonstrated by executing OS commands. This occurs because csrf_callback() produces a "CSRF token expired" error and a Try Again button when a CSRF token is missing. > MITRE Terms of Use apply – see LICENSE‑MITRE.txt