CVE-2019-25368

Source
https://cve.org/CVERecord?id=CVE-2019-25368
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2019-25368.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2019-25368
Published
2026-02-15T14:16:06.190Z
Modified
2026-08-07T11:48:20.918466181Z
Severity
  • 5.4 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N CVSS Calculator
Summary
[none]
Details

OPNsense 19.1 contains multiple cross-site scripting vulnerabilities in the diagbackup.php endpoint that allow attackers to inject malicious scripts through multiple parameters including GDriveGDriveEmail, GDriveGDriveFolderID, GDriveGDriveBackupCount, Nextcloudurl, Nextclouduser, Nextcloudpassword, Nextcloudpasswordencryption, and Nextcloudbackupdir. Attackers can submit POST requests with script payloads in these parameters to execute arbitrary JavaScript in the context of authenticated administrator sessions.

References

Affected packages

Git / github.com/opnsense/core

Affected ranges

Type
GIT
Repo
https://github.com/opnsense/core
Events
Database specific
{
    "cpe": "cpe:2.3:a:opnsense:opnsense:19.1:*:*:*:*:*:*:*",
    "extracted_events": [
        {
            "introduced": "19.1"
        },
        {
            "last_affected": "19.1"
        }
    ],
    "source": "CPE_STRING"
}

Affected versions

19.*
19.1
19.1.r

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2019-25368.json"