Description
OPNsense 19.1 contains multiple cross-site scripting vulnerabilities in the diag_backup.php endpoint that allow attackers to inject malicious scripts through multiple parameters including GDrive_GDriveEmail, GDrive_GDriveFolderID, GDrive_GDriveBackupCount, Nextcloud_url, Nextcloud_user, Nextcloud_password, Nextcloud_password_encryption, and Nextcloud_backupdir. Attackers can submit POST requests with script payloads in these parameters to execute arbitrary JavaScript in the context of authenticated administrator sessions.
INFO
Published Date :
2026-02-15T13:58:51.292Z
Last Modified :
2026-03-05T01:26:16.328Z
Source :
VulnCheck
AFFECTED PRODUCTS
The following products are affected by CVE-2019-25368 vulnerability.
| Vendors | Products |
|---|---|
| Opnsense |
|
REFERENCES
Here, you will find a curated list of external links that provide in-depth information to CVE-2019-25368.