A command injection vulnerability in the function...
High severity
Unreviewed
Published
Mar 18, 2023
to the GitHub Advisory Database
•
Updated Jul 14, 2023
Description
Published by the National Vulnerability Database
Mar 17, 2023
Published to the GitHub Advisory Database
Mar 18, 2023
Last updated
Jul 14, 2023
A command injection vulnerability in the function restore_rrddata() of Netgate pfSense v2.7.0 allows authenticated attackers to execute arbitrary commands via manipulating the contents of an XML file supplied to the component config.xml.
References