Vulnerability record · CVE-2019-12347 · published 29 May 2019
CVE-2019-12347: pfSense stored XSS in ACME account key Name/Description fields
Netgate · Pfsense
pfSense 2.4.4-p3 fails to validate input in the Name and Description fields handled by acme_accountkeys_edit.php, allowing a stored cross-site scripting payload to be saved. The injected script then executes in the browser of anyone viewing the affected page, which matters because pfSense is a security appliance whose admin interface is a high-value target.
Description
In pfSense 2.4.4-p3, a stored XSS vulnerability occurs when attackers inject a payload into the Name or Description field via an acme_accountkeys_edit.php action. The vulnerability occurs due to input validation errors.
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Automated analysis
medium priorityCVSS rates it medium (6.1) and it requires user interaction, but the target is a security appliance admin interface and public exploit code exists.
What it is
pfSense 2.4.4-p3 fails to validate input in the Name and Description fields handled by acme_accountkeys_edit.php, allowing a stored cross-site scripting payload to be saved. The injected script then executes in the browser of anyone viewing the affected page, which matters because pfSense is a security appliance whose admin interface is a high-value target.
Impact
An attacker can run arbitrary script in the context of a pfSense administrator's session, enabling session theft, credential capture or unauthorized actions through the admin UI. The CVSS scope change (S:C) reflects that the impact can extend beyond the vulnerable component.
Attack surface
Reached over the network through the pfSense web interface; the CVSS vector shows no privileges required (PR:N) but user interaction required (UI:R), meaning a victim must view the page containing the stored payload.
Exploitation
Not listed in CISA KEV, but EPSS is high at roughly 0.586 (99th percentile) and multiple references are tagged Exploit, indicating public proof-of-concept code exists.
What to do
- Upgrade pfSense to a release containing the fix referenced in the vendor commit and advisory; patch first.
- Restrict access to the pfSense web interface to trusted management networks and avoid exposing it to the internet.
- Enforce strict output encoding and input validation on the Name and Description fields in acme_accountkeys_edit.php if running an unpatched build.
- Review ACME account key entries for unexpected or script-like content and remove any suspicious values.
Detection
- Search pfSense ACME account key Name and Description fields for HTML or script tags and other encoded payload patterns.
- Monitor web server and audit logs for requests to acme_accountkeys_edit.php with suspicious parameter values.
- Alert on anomalous admin session activity or unexpected configuration changes following ACME key edits.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| http://packetstormsecurity.com/files/153112/pfSense-2.4.4-p3-Cross-Site-Scripting.html | ExploitThird Party AdvisoryVDB Entry |
| https://ctrsec.io/index.php/2019/05/28/stored-xss-acme-pfsense-2-4-4-p3/ | ExploitPatchThird Party Advisory |
| https://github.com/pfsense/FreeBSD-ports/commit/504909564079e540689dbdbed3a579483c614275 | PatchThird Party Advisory |
| https://redmine.pfsense.org/issues/9554#change-40729 | ExploitVendor Advisory |
| https://www.pfsense.org/download/ | Vendor Advisory |
| http://packetstormsecurity.com/files/153112/pfSense-2.4.4-p3-Cross-Site-Scripting.html | ExploitThird Party AdvisoryVDB Entry |
| https://ctrsec.io/index.php/2019/05/28/stored-xss-acme-pfsense-2-4-4-p3/ | ExploitPatchThird Party Advisory |
| https://github.com/pfsense/FreeBSD-ports/commit/504909564079e540689dbdbed3a579483c614275 | PatchThird Party Advisory |
| https://redmine.pfsense.org/issues/9554#change-40729 | ExploitVendor Advisory |
| https://www.pfsense.org/download/ | Vendor Advisory |
Track CVE-2019-12347 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2019-12347), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.