CVE-2019-16915

Severity CVSS v4.0:
Pending analysis
Type:
CWE-22 Path Traversal
Publication date:
26/09/2019
Last modified:
21/07/2021

Description

An issue was discovered in pfSense through 2.4.4-p3. widgets/widgets/picture.widget.php uses the widgetkey parameter directly without sanitization (e.g., a basename call) for a pathname to file_get_contents or file_put_contents.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:netgate:pfsense:*:*:*:*:*:*:*:* 2.4.4 (excluding)
cpe:2.3:a:netgate:pfsense:2.4.4:-:*:*:*:*:*:*
cpe:2.3:a:netgate:pfsense:2.4.4:p1:*:*:*:*:*:*
cpe:2.3:a:netgate:pfsense:2.4.4:p2:*:*:*:*:*:*
cpe:2.3:a:netgate:pfsense:2.4.4:p3:*:*:*:*:*:*