#VU21374 Input validation error in pfsense - CVE-2019-16915
Published: September 27, 2019 / Updated: June 10, 2020
pfsense
Rubicon Communications
Description
The vulnerability allows a remote attacker to read and write arbitrary files on the system.
The vulnerability exists due to insufficient validation of user-supplied input in "/widgets/widgets/picture.widget.php" when processing data passed via the "widgetkey" parameter. A remote attacker authenticated attacker can read and write arbitrary files on the system.