RULE(RULE ID:710143)

Rule General Information
Release Date: 2015-10-06
Rule Name: WEB-OTHER Pfsense Webgui Zone Parameter Cross-site Scripting Vulnerability -1 (CVE-2015-4029)
Severity:
CVE ID:
Rule Protection Details
Description: Cross-site scripting (XSS) vulnerability in the WebGUI in pfSense before 2.2.3 allows remote attackers to inject arbitrary web script or HTML via the zone parameter in a del action to services_captiveportal_zones.php.
Impact: An attacker can conduct a cross-site scripting attack to inject malicious client-side scripts into web pages viewed by other users, or to bypass access controls such as the same-origin policy, if affected version is installed.
Affected OS: Windows
Reference: http://seclists.org/fulldisclosure/2015/Jul/66
https://www.pfsense.org/security/advisories/pfSense-SA-15_06.webgui.asc
Solutions
More advisories have been published on the website, please visit for more suggestions:
https://www.pfsense.org/security/advisories/pfSense-SA-15_06.webgui.asc