CyberRota Analysis
This vulnerability has an unknown severity rating. See the original NVD description below for full technical details.
Original NVD Description
In Deciso OPNsense before 25.7.4, when creating an "Interfaces: Devices: Point-to-Point" entry, the value of the parameter ptpid is not sanitized of HTML-related characters/strings. This value is directly displayed when visiting the page/interfaces_assign.php, which can result in stored cross-site scripting. The attacker must be authenticated with at-least "Interfaces: PPPs: Edit" permission. This vulnerability has been addressed by the vendor in the product release notes asĀ "ui: legacy_html_escape_form_data() was not escaping keys only data elements."