CVE-2019-25368

OPNsense 19.1 contains multiple cross-site scripting vulnerabilities in the diag_backup.php endpoint that allow attackers to inject malicious scripts through multiple parameters including GDrive_GDriveEmail, GDrive_GDriveFolderID, GDrive_GDriveBackupCount, Nextcloud_url, Nextcloud_user, Nextcloud_password, Nextcloud_password_encryption, and Nextcloud_backupdir. Attackers can submit POST requests with script payloads in these parameters to execute arbitrary JavaScript in the context of authenticated administrator sessions.
Configurations

Configuration 1 (hide)

cpe:2.3:a:opnsense:opnsense:19.1:*:*:*:*:*:*:*

History

18 Feb 2026, 19:16

Type Values Removed Values Added
CPE cpe:2.3:a:opnsense:opnsense:19.1:*:*:*:*:*:*:*
References () https://forum.opnsense.org/index.php?topic=11469.0 - () https://forum.opnsense.org/index.php?topic=11469.0 - Release Notes
References () https://opnsense.org - () https://opnsense.org - Product
References () https://www.exploit-db.com/exploits/46351 - () https://www.exploit-db.com/exploits/46351 - Exploit, Third Party Advisory, VDB Entry
References () https://www.vulncheck.com/advisories/opnsense-reflected-xss-via-diagbackupphp - () https://www.vulncheck.com/advisories/opnsense-reflected-xss-via-diagbackupphp - Broken Link
First Time Opnsense opnsense
Opnsense

18 Feb 2026, 17:52

Type Values Removed Values Added
Summary
  • (es) OPNsense 19.1 contiene múltiples vulnerabilidades de cross-site scripting en el endpoint diag_backup.PHP que permiten a los atacantes inyectar scripts maliciosos a través de múltiples parámetros, incluyendo GDrive_GDriveEmail, GDrive_GDriveFolderID, GDrive_GDriveBackupCount, Nextcloud_url, Nextcloud_user, Nextcloud_password, Nextcloud_password_encryption y Nextcloud_backupdir. Los atacantes pueden enviar solicitudes POST con cargas útiles de script en estos parámetros para ejecutar JavaScript arbitrario en el contexto de sesiones de administrador autenticadas.

15 Feb 2026, 14:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-02-15 14:16

Updated : 2026-02-18 19:16


NVD link : CVE-2019-25368

Mitre link : CVE-2019-25368

CVE.ORG link : CVE-2019-25368


JSON object : View

Products Affected

opnsense

  • opnsense
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')