Vulnerability record · CVE-2023-42327 · published 14 November 2023
CVE-2023-42327: pfSense getserviceproviders.php reflected XSS enables privilege gain
Netgate · Pfsense
Netgate pfSense 2.7.0 contains a cross-site scripting flaw in getserviceproviders.php, where a crafted URL injects script into the page. Because the affected page sits in the web GUI, successful exploitation can let an attacker act with the privileges of a logged-in administrator.
Description
Cross Site Scripting (XSS) vulnerability in Netgate pfSense v.2.7.0 allows a remote attacker to gain privileges via a crafted URL to the getserviceproviders.php page.
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Automated analysis
medium priorityRequires an authenticated user to click a crafted link, but the high EPSS and public exploit detail raise the practical risk.
What it is
Netgate pfSense 2.7.0 contains a cross-site scripting flaw in getserviceproviders.php, where a crafted URL injects script into the page. Because the affected page sits in the web GUI, successful exploitation can let an attacker act with the privileges of a logged-in administrator.
Impact
An attacker can execute script in a victim's browser session and, per the description, gain privileges, potentially leading to configuration changes or further compromise of the firewall.
Attack surface
Reached over the network through the pfSense web GUI at getserviceproviders.php; the CVSS vector requires low privileges (PR:L) and user interaction (UI:R), so a logged-in user must be induced to open a crafted URL.
Exploitation
Not listed in CISA KEV, but EPSS is high at 0.55356 (99th percentile) and the vendor advisory is tagged Exploit, indicating public exploit detail exists.
What to do
- Upgrade pfSense to a version containing the fix from Netgate advisory pfSense-SA-23_08.webgui
- Restrict web GUI access to trusted management networks and avoid exposing it to the internet
- Require administrators to log out and avoid following untrusted links while authenticated to the GUI
- Apply input validation and output encoding to getserviceproviders.php parameters if running an unpatched build
Detection
- Review web server and pfSense GUI logs for requests to getserviceproviders.php containing script tags or encoded payloads
- Monitor for anomalous administrative actions or configuration changes following GUI access
- Use browser or proxy alerts for reflected script execution on the pfSense management interface
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2023-42327 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2023-42327), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.