CVE-2020-11457 | pfSense up to 2.4.4 WebGUI system_usermanager_addprivs.php descr Stored cross site scripting (ID 157104 / EDB-48300)
A vulnerability was found in pfSense up to 2.4.4. It has been declared as problematic. This vulnerability affects unknown code of the file system_usermanager_addprivs.php of the component WebGUI. The manipulation of the argument descr as part of Parameter leads to cross site scripting (Stored).
This vulnerability was named CVE-2020-11457. The attack can be initiated remotely. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.