CVE-2019-16914: Netgate Pfsense
Medium severity, CVSS 6.1. EPSS: 2% chance of exploitation in the next 30 days.
An XSS issue was discovered in pfSense through 2.4.4-p3. In services_captiveportal_mac.php, the username and delmac parameters are displayed without sanitization.
Affected products
- Netgate Pfsense: before 2.4.4 (fixed in 2.4.4); version 2.4.4 only
Published 2019-09-26. Last modified 2026-06-17.