CRITICAL

CVE-2023-39007

CVSS v3

9.6

CRITICAL

EPSS Score

48.5%

exploit probability

CISA KEV

No

known exploited

Exploitation

SSVC status

Description

/ui/cron/item/open in the Cron component of OPNsense Community Edition before 23.7 and Business Edition before 23.4.2 allows XSS via openAction in app/controllers/OPNsense/Cron/ItemController.php.

Technical details

Published
8/9/2023

Frequently asked questions

What is CVE-2023-39007?

/ui/cron/item/open in the Cron component of OPNsense Community Edition before 23.7 and Business Edition before 23.4.2 allows XSS via openAction in app/controllers/OPNsense/Cron/ItemController.php.

Is CVE-2023-39007 actively exploited?

Active exploitation of CVE-2023-39007 has not been confirmed. The EPSS score is 48.5%, indicating the estimated probability of exploitation in the next 30 days.

What is the CVSS score for CVE-2023-39007?

CVE-2023-39007 has a CVSS v3 base score of 9.6 (CRITICAL severity).

Is CVE-2023-39007 affecting your environment?

Use isMalicious to check if any of your IPs or domains are associated with this vulnerability's IOCs.