Vulnerability record · CVE-2023-42325 · published 14 November 2023
CVE-2023-42325: pfSense WebGUI status_logs_filter_dynamic.php reflected XSS
Netgate · Pfsense
Netgate pfSense 2.7.0 contains a reflected cross-site scripting flaw in the status_logs_filter_dynamic.php page, where a crafted URL can inject script into the response. Because the page is part of the administrative WebGUI, successful exploitation can run script in the context of a logged-in administrator and lead to privilege gain.
Description
Cross Site Scripting (XSS) vulnerability in Netgate pfSense v.2.7.0 allows a remote attacker to gain privileges via a crafted url to the status_logs_filter_dynamic.php page.
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Automated analysis
medium priorityCVSS rates it medium (5.4) and it requires an authenticated, interacting victim, but the high EPSS and vendor Exploit tag raise the practical risk for exposed WebGUI instances.
What it is
Netgate pfSense 2.7.0 contains a reflected cross-site scripting flaw in the status_logs_filter_dynamic.php page, where a crafted URL can inject script into the response. Because the page is part of the administrative WebGUI, successful exploitation can run script in the context of a logged-in administrator and lead to privilege gain.
Impact
An attacker who lures a privileged pfSense user to a crafted URL can execute script in that user's browser session, potentially performing administrative actions or stealing session data. The CVSS scope change (S:C) reflects that the impact can extend beyond the vulnerable component.
Attack surface
Reached over the network via a crafted URL to the WebGUI page status_logs_filter_dynamic.php. The vector requires low privileges (PR:L) and user interaction (UI:R), so the victim must be authenticated and induced to open the link.
Exploitation
Not listed in CISA KEV and no ransomware association is recorded. EPSS is high (0.57918, 99th percentile) and the vendor advisory is tagged Exploit, indicating public exploit detail exists, but the record does not confirm active exploitation.
What to do
- Apply the Netgate pfSense security advisory SA-23_09 update for the WebGUI; patch first.
- Restrict WebGUI access to trusted management networks and avoid exposing it to the internet.
- Require administrators to re-authenticate and rotate credentials if a suspicious crafted URL was opened.
- Train privileged users not to follow untrusted links to pfSense admin pages.
Detection
- Review WebGUI access logs for requests to status_logs_filter_dynamic.php containing script-like or encoded payloads in query parameters.
- Alert on anomalous administrative sessions or actions following visits to crafted URLs.
- Monitor for unexpected outbound connections or credential use from administrator browsers.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2023-42325 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2023-42325), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.