← Vulnerability feed

Vulnerability record · CVE-2019-12347 · published 29 May 2019

CVE-2019-12347: pfSense stored XSS in ACME account key Name/Description fields

Netgate · Pfsense

pfSense 2.4.4-p3 fails to validate input in the Name and Description fields handled by acme_accountkeys_edit.php, allowing a stored cross-site scripting payload to be saved. The injected script then executes in the browser of anyone viewing the affected page, which matters because pfSense is a security appliance whose admin interface is a high-value target.

6.1 CVSS 3.0 Medium EPSS 59% · top 0.9% CWE-79 · Cross-site scripting
6.1CVSS 3.0 base score, v2 4.3
59%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
10References, 6 tagged exploit
17 Jun 2026Last modified by NVD

Description

In pfSense 2.4.4-p3, a stored XSS vulnerability occurs when attackers inject a payload into the Name or Description field via an acme_accountkeys_edit.php action. The vulnerability occurs due to input validation errors.

CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 19 September 2026. Confidence: high.

medium priorityCVSS rates it medium (6.1) and it requires user interaction, but the target is a security appliance admin interface and public exploit code exists.

What it is

pfSense 2.4.4-p3 fails to validate input in the Name and Description fields handled by acme_accountkeys_edit.php, allowing a stored cross-site scripting payload to be saved. The injected script then executes in the browser of anyone viewing the affected page, which matters because pfSense is a security appliance whose admin interface is a high-value target.

Impact

An attacker can run arbitrary script in the context of a pfSense administrator's session, enabling session theft, credential capture or unauthorized actions through the admin UI. The CVSS scope change (S:C) reflects that the impact can extend beyond the vulnerable component.

Attack surface

Reached over the network through the pfSense web interface; the CVSS vector shows no privileges required (PR:N) but user interaction required (UI:R), meaning a victim must view the page containing the stored payload.

Exploitation

Not listed in CISA KEV, but EPSS is high at roughly 0.586 (99th percentile) and multiple references are tagged Exploit, indicating public proof-of-concept code exists.

What to do

  • Upgrade pfSense to a release containing the fix referenced in the vendor commit and advisory; patch first.
  • Restrict access to the pfSense web interface to trusted management networks and avoid exposing it to the internet.
  • Enforce strict output encoding and input validation on the Name and Description fields in acme_accountkeys_edit.php if running an unpatched build.
  • Review ACME account key entries for unexpected or script-like content and remove any suspicious values.

Detection

  • Search pfSense ACME account key Name and Description fields for HTML or script tags and other encoded payload patterns.
  • Monitor web server and audit logs for requests to acme_accountkeys_edit.php with suspicious parameter values.
  • Alert on anomalous admin session activity or unexpected configuration changes following ACME key edits.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2019-12347 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2019-16915Netgate pfsense path traversal vulnerabilityAn issue was discovered in pfSense through 2.4.4-p3. widgets/widgets/picture.widget.php uses the widgetkey parameter directly without sanitization (e…EPSS 3.7%9.8CVE-2019-12585Apcupsd os command injection vulnerabilityApcupsd 0.3.91_5, as used in pfSense through 2.4.4-RELEASE-p3 and other products, has an Arbitrary Command Execution issue in apcupsd_status.php.EPSS 5.0%9.6CVE-2020-21487Netgate pfsense cross-site scripting vulnerabilityCross Site Scripting vulnerability found in Netgate pfSense 2.4.4 and ACME package v.0.6.3 allows attackers to execute arbitrary code via the RootFol…EPSS 0.67%8.8CVE-2023-48123pfSense web GUI packet_capture.php remote code executionpfSense Plus 23.05.1 and earlier and pfSense CE 2.7.0 allow a remote attacker to execute arbitrary code through a crafted request to packet_capture.p…EPSS 68%analysed8.8CVE-2023-42326pfSense WebGUI GIF/GRE Interface Command InjectionNetgate pfSense 2.7.0 contains a command injection flaw in the interfaces_gif_edit.php and interfaces_gre_edit.php WebGUI components. A remote attack…EPSS 64%analysed8.8CVE-2023-27253pfSense restore_rrddata() command injection via crafted XML configNetgate pfSense 2.7.0 contains a command injection flaw in the restore_rrddata() function. An authenticated attacker can supply a crafted XML file to…EPSS 90%analysed8.8CVE-2022-24299Netgate pfsense improper input validation vulnerabilityImproper input validation vulnerability in pfSense CE and pfSense Plus (pfSense CE software versions prior to 2.6.0 and pfSense Plus software version…EPSS 1.9%8.8CVE-2022-26019Netgate pfsense path traversal vulnerabilityImproper access control vulnerability in pfSense CE and pfSense Plus (pfSense CE software versions prior to 2.6.0 and pfSense Plus software versions …EPSS 4.5%

Source: NIST National Vulnerability Database (record CVE-2019-12347), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.