An XSS issue was discovered in pfSense through 2.4.4-p3. In services_captiveportal_mac.php, the username and delmac parameters are displayed without sanitization.
| Software | From | Fixed in |
|---|---|---|
| netgate / pfsense | - | 2.4.4 |
| netgate / pfsense | 2.4.4-p1 | 2.4.4-p1.x |
| netgate / pfsense | 2.4.4-p3 | 2.4.4-p3.x |
| netgate / pfsense | 2.4.4-p2 | 2.4.4-p2.x |
| netgate / pfsense | 2.4.4 | 2.4.4.x |