← Vulnerability feed

Vulnerability record · CVE-2023-42327 · published 14 November 2023

CVE-2023-42327: pfSense getserviceproviders.php reflected XSS enables privilege gain

Netgate · Pfsense

Netgate pfSense 2.7.0 contains a cross-site scripting flaw in getserviceproviders.php, where a crafted URL injects script into the page. Because the affected page sits in the web GUI, successful exploitation can let an attacker act with the privileges of a logged-in administrator.

5.4 CVSS 3.1 Medium EPSS 55% · top 1.0% CWE-79 · Cross-site scripting
5.4CVSS 3.1 base score
55%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
4References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

Cross Site Scripting (XSS) vulnerability in Netgate pfSense v.2.7.0 allows a remote attacker to gain privileges via a crafted URL to the getserviceproviders.php page.

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 19 September 2026. Confidence: medium.

medium priorityRequires an authenticated user to click a crafted link, but the high EPSS and public exploit detail raise the practical risk.

What it is

Netgate pfSense 2.7.0 contains a cross-site scripting flaw in getserviceproviders.php, where a crafted URL injects script into the page. Because the affected page sits in the web GUI, successful exploitation can let an attacker act with the privileges of a logged-in administrator.

Impact

An attacker can execute script in a victim's browser session and, per the description, gain privileges, potentially leading to configuration changes or further compromise of the firewall.

Attack surface

Reached over the network through the pfSense web GUI at getserviceproviders.php; the CVSS vector requires low privileges (PR:L) and user interaction (UI:R), so a logged-in user must be induced to open a crafted URL.

Exploitation

Not listed in CISA KEV, but EPSS is high at 0.55356 (99th percentile) and the vendor advisory is tagged Exploit, indicating public exploit detail exists.

What to do

  • Upgrade pfSense to a version containing the fix from Netgate advisory pfSense-SA-23_08.webgui
  • Restrict web GUI access to trusted management networks and avoid exposing it to the internet
  • Require administrators to log out and avoid following untrusted links while authenticated to the GUI
  • Apply input validation and output encoding to getserviceproviders.php parameters if running an unpatched build

Detection

  • Review web server and pfSense GUI logs for requests to getserviceproviders.php containing script tags or encoded payloads
  • Monitor for anomalous administrative actions or configuration changes following GUI access
  • Use browser or proxy alerts for reflected script execution on the pfSense management interface

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2023-42327 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2019-16915Netgate pfsense path traversal vulnerabilityAn issue was discovered in pfSense through 2.4.4-p3. widgets/widgets/picture.widget.php uses the widgetkey parameter directly without sanitization (e…EPSS 3.7%9.8CVE-2019-12585Apcupsd os command injection vulnerabilityApcupsd 0.3.91_5, as used in pfSense through 2.4.4-RELEASE-p3 and other products, has an Arbitrary Command Execution issue in apcupsd_status.php.EPSS 5.0%9.6CVE-2020-21487Netgate pfsense cross-site scripting vulnerabilityCross Site Scripting vulnerability found in Netgate pfSense 2.4.4 and ACME package v.0.6.3 allows attackers to execute arbitrary code via the RootFol…EPSS 0.67%8.8CVE-2023-48123pfSense web GUI packet_capture.php remote code executionpfSense Plus 23.05.1 and earlier and pfSense CE 2.7.0 allow a remote attacker to execute arbitrary code through a crafted request to packet_capture.p…EPSS 68%analysed8.8CVE-2023-42326pfSense WebGUI GIF/GRE Interface Command InjectionNetgate pfSense 2.7.0 contains a command injection flaw in the interfaces_gif_edit.php and interfaces_gre_edit.php WebGUI components. A remote attack…EPSS 64%analysed8.8CVE-2023-27253pfSense restore_rrddata() command injection via crafted XML configNetgate pfSense 2.7.0 contains a command injection flaw in the restore_rrddata() function. An authenticated attacker can supply a crafted XML file to…EPSS 90%analysed8.8CVE-2022-24299Netgate pfsense improper input validation vulnerabilityImproper input validation vulnerability in pfSense CE and pfSense Plus (pfSense CE software versions prior to 2.6.0 and pfSense Plus software version…EPSS 1.9%8.8CVE-2022-26019Netgate pfsense path traversal vulnerabilityImproper access control vulnerability in pfSense CE and pfSense Plus (pfSense CE software versions prior to 2.6.0 and pfSense Plus software versions …EPSS 4.5%

Source: NIST National Vulnerability Database (record CVE-2023-42327), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.