CVE-2023-38997 Information

Description

A directory traversal vulnerability in the Captive Portal templates of OPNsense before 23.7 allows attackers to execute arbitrary system commands as root via a crafted ZIP archive.

Reference

https://github.com/opnsense/core/commit/448762d440b51574f1906c0ec2f5ea6dc4f16eb2 https://logicaltrust.net/blog/2023/08/opnsense.html

Share on: