{"id":3367,"date":"2026-02-18T20:01:21","date_gmt":"2026-02-18T20:01:21","guid":{"rendered":"https:\/\/www.ucartz.com\/updates\/opnsense-cross-site-scripting-vulnerability-cve-2019-25368-medium-severity\/"},"modified":"2026-02-18T20:01:21","modified_gmt":"2026-02-18T20:01:21","slug":"opnsense-cross-site-scripting-vulnerability-cve-2019-25368-medium-severity","status":"publish","type":"post","link":"https:\/\/www.ucartz.com\/updates\/opnsense-cross-site-scripting-vulnerability-cve-2019-25368-medium-severity\/","title":{"rendered":"OPNsense Cross-Site Scripting Vulnerability (CVE-2019-25368) \u2014 Medium Severity"},"content":{"rendered":"<p>A notable security flaw, identified as CVE-2019-25368, has been discovered in OPNsense 19.1. This vulnerability involves multiple Cross-Site Scripting (XSS) issues that could allow an attacker to inject harmful code into your system. For users managing OPNsense installations, understanding this vulnerability and applying necessary updates is crucial for maintaining a secure network environment.<\/p>\n<p>Cross-Site Scripting, or XSS, is a type of security flaw often found in web applications. It allows attackers to inject malicious scripts into web pages viewed by other users. In this specific case, the vulnerability exists within the <code>diag_backup.php<\/code> section of OPNsense. Attackers could craft special web requests (POST requests) that include these malicious scripts in several parameters, such as GDrive_GDriveEmail, GDrive_GDriveFolderID, Nextcloud_url, and others. If a logged-in administrator then views a page affected by this, the attacker&#8217;s script could run in their browser. This means the attacker could potentially do things an administrator can do, like change settings or steal session information, all without the administrator knowing.<\/p>\n<h2>CVE Details<\/h2>\n<ul>\n<li><strong>Product:<\/strong> OPNsense<\/li>\n<li><strong>Published Date:<\/strong> February 15, 2026<\/li>\n<li><strong>Severity:<\/strong> Medium<\/li>\n<li><strong>Status:<\/strong> Analyzed<\/li>\n<\/ul>\n<h2>Affected Products<\/h2>\n<p>The vulnerability primarily affects <strong>OPNsense version 19.1<\/strong>.<\/p>\n<h2>Current Status<\/h2>\n<p>This vulnerability has been thoroughly analyzed. The good news is that fixes were released shortly after its discovery. It&#8217;s important for users of the affected version to take action to protect their systems.<\/p>\n<h2>Severity Level<\/h2>\n<p>Rated as &#8220;Medium&#8221; severity with a CVSS score of 5.4, this vulnerability poses a significant risk because it targets administrative sessions. An attacker exploiting an XSS vulnerability within an authenticated administrator session could potentially execute arbitrary JavaScript commands. This could lead to unauthorized actions, data manipulation, or further compromise of the firewall if not addressed. While it requires an authenticated session, the potential impact highlights the importance of timely patching.<\/p>\n<h2>Possible Solutions<\/h2>\n<p>Fortunately, the OPNsense team promptly addressed these XSS vulnerabilities. The forum announcement indicates that &#8220;Uncoordinated cross site scripting issues have been fixed&#8221; in the <strong>OPNsense 19.1.1 release<\/strong>. Therefore, the most effective solution is to update your OPNsense installation to version 19.1.1 or a later stable release. Always ensure your systems are running the latest patched versions to benefit from critical security updates and maintain robust protection against known threats.<\/p>\n<p>Regularly checking for and applying software updates is a fundamental practice in cybersecurity. For OPNsense users, staying current with releases helps safeguard your network infrastructure against evolving threats.<\/p>\n<h2>References<\/h2>\n<p>\n    https:\/\/forum.opnsense.org\/index.php?topic=11469.0<br \/>\n    https:\/\/opnsense.org<br \/>\n    https:\/\/www.exploit-db.com\/exploits\/46351<br \/>\n    https:\/\/www.vulncheck.com\/advisories\/opnsense-reflected-xss-via-diagbackupphp<\/p>\n","protected":false},"excerpt":{"rendered":"<p>A notable security flaw, identified as CVE-2019-25368, has been discovered in OPNsense 19.1. This vulnerability involves multiple Cross-Site Scripting (XSS) issues that could allow an attacker to inject harmful code into your system. For users managing OPNsense installations, understanding this vulnerability and applying necessary updates is crucial for maintaining a secure network environment. Cross-Site Scripting, [&hellip;]<\/p>\n","protected":false},"author":17,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[817,1021,1020,695,692],"class_list":["post-3367","post","type-post","status-publish","format-standard","hentry","category-security","tag-cross-site-scripting","tag-network-firewall","tag-opnsense","tag-web-security","tag-xss"],"blocksy_meta":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v28.5 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>OPNsense Cross-Site Scripting Vulnerability (CVE-2019-25368) \u2014 Medium Severity - Web Hosting and IT Consultancy Services<\/title>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.ucartz.com\/updates\/opnsense-cross-site-scripting-vulnerability-cve-2019-25368-medium-severity\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"OPNsense Cross-Site Scripting Vulnerability (CVE-2019-25368) \u2014 Medium Severity - Web Hosting and IT Consultancy Services\" \/>\n<meta property=\"og:description\" content=\"A notable security flaw, identified as CVE-2019-25368, has been discovered in OPNsense 19.1. This vulnerability involves multiple Cross-Site Scripting (XSS) issues that could allow an attacker to inject harmful code into your system. For users managing OPNsense installations, understanding this vulnerability and applying necessary updates is crucial for maintaining a secure network environment. Cross-Site Scripting, [&hellip;]\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.ucartz.com\/updates\/opnsense-cross-site-scripting-vulnerability-cve-2019-25368-medium-severity\/\" \/>\n<meta property=\"og:site_name\" content=\"Web Hosting and IT Consultancy Services\" \/>\n<meta property=\"article:published_time\" content=\"2026-02-18T20:01:21+00:00\" \/>\n<meta name=\"author\" content=\"Alex Joseph\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Alex Joseph\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"2 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/www.ucartz.com\\\/updates\\\/opnsense-cross-site-scripting-vulnerability-cve-2019-25368-medium-severity\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.ucartz.com\\\/updates\\\/opnsense-cross-site-scripting-vulnerability-cve-2019-25368-medium-severity\\\/\"},\"author\":{\"name\":\"Alex Joseph\",\"@id\":\"https:\\\/\\\/www.ucartz.com\\\/updates\\\/#\\\/schema\\\/person\\\/1ba9bfab02a76dee216c9f55bb634e56\"},\"headline\":\"OPNsense Cross-Site Scripting Vulnerability (CVE-2019-25368) \u2014 Medium Severity\",\"datePublished\":\"2026-02-18T20:01:21+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/www.ucartz.com\\\/updates\\\/opnsense-cross-site-scripting-vulnerability-cve-2019-25368-medium-severity\\\/\"},\"wordCount\":417,\"commentCount\":0,\"publisher\":{\"@id\":\"https:\\\/\\\/www.ucartz.com\\\/updates\\\/#organization\"},\"keywords\":[\"Cross Site Scripting\",\"Network Firewall\",\"OPNsense\",\"Web Security\",\"Xss\"],\"articleSection\":[\"Security\"],\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\\\/\\\/www.ucartz.com\\\/updates\\\/opnsense-cross-site-scripting-vulnerability-cve-2019-25368-medium-severity\\\/#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/www.ucartz.com\\\/updates\\\/opnsense-cross-site-scripting-vulnerability-cve-2019-25368-medium-severity\\\/\",\"url\":\"https:\\\/\\\/www.ucartz.com\\\/updates\\\/opnsense-cross-site-scripting-vulnerability-cve-2019-25368-medium-severity\\\/\",\"name\":\"OPNsense Cross-Site Scripting Vulnerability (CVE-2019-25368) \u2014 Medium Severity - Web Hosting and IT Consultancy Services\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.ucartz.com\\\/updates\\\/#website\"},\"datePublished\":\"2026-02-18T20:01:21+00:00\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/www.ucartz.com\\\/updates\\\/opnsense-cross-site-scripting-vulnerability-cve-2019-25368-medium-severity\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/www.ucartz.com\\\/updates\\\/opnsense-cross-site-scripting-vulnerability-cve-2019-25368-medium-severity\\\/\"]}]},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/www.ucartz.com\\\/updates\\\/opnsense-cross-site-scripting-vulnerability-cve-2019-25368-medium-severity\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/www.ucartz.com\\\/updates\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"OPNsense Cross-Site Scripting Vulnerability (CVE-2019-25368) \u2014 Medium Severity\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/www.ucartz.com\\\/updates\\\/#website\",\"url\":\"https:\\\/\\\/www.ucartz.com\\\/updates\\\/\",\"name\":\"Web Hosting and IT Consultancy Services\",\"description\":\"Discover the Potential of Digital Transformation through Effortless Hosting and Professional IT Consulting!\",\"publisher\":{\"@id\":\"https:\\\/\\\/www.ucartz.com\\\/updates\\\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/www.ucartz.com\\\/updates\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/www.ucartz.com\\\/updates\\\/#organization\",\"name\":\"Web Hosting and IT Consultancy Services\",\"url\":\"https:\\\/\\\/www.ucartz.com\\\/updates\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.ucartz.com\\\/updates\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/www.ucartz.com\\\/updates\\\/wp-content\\\/uploads\\\/2025\\\/12\\\/ucartzLogo-1.png\",\"contentUrl\":\"https:\\\/\\\/www.ucartz.com\\\/updates\\\/wp-content\\\/uploads\\\/2025\\\/12\\\/ucartzLogo-1.png\",\"width\":165,\"height\":50,\"caption\":\"Web Hosting and IT Consultancy Services\"},\"image\":{\"@id\":\"https:\\\/\\\/www.ucartz.com\\\/updates\\\/#\\\/schema\\\/logo\\\/image\\\/\"}},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/www.ucartz.com\\\/updates\\\/#\\\/schema\\\/person\\\/1ba9bfab02a76dee216c9f55bb634e56\",\"name\":\"Alex Joseph\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/0969fa5fefa2739cbd6fd5eaf04fed619e19f40d42e4a42650090606944ff747?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/0969fa5fefa2739cbd6fd5eaf04fed619e19f40d42e4a42650090606944ff747?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/0969fa5fefa2739cbd6fd5eaf04fed619e19f40d42e4a42650090606944ff747?s=96&d=mm&r=g\",\"caption\":\"Alex Joseph\"},\"description\":\"Alex Joseph is a Senior Support Staff professional with deep experience in server management, web hosting technologies, and cybersecurity operations. He works daily with Linux servers, cloud platforms, performance tuning, and security hardening, giving him strong real-world technical knowledge. Along with his support role, he write about security best practices, hosting infrastructure, and software management.\",\"url\":\"https:\\\/\\\/www.ucartz.com\\\/updates\\\/author\\\/alexjoseph\\\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"OPNsense Cross-Site Scripting Vulnerability (CVE-2019-25368) \u2014 Medium Severity - Web Hosting and IT Consultancy Services","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.ucartz.com\/updates\/opnsense-cross-site-scripting-vulnerability-cve-2019-25368-medium-severity\/","og_locale":"en_US","og_type":"article","og_title":"OPNsense Cross-Site Scripting Vulnerability (CVE-2019-25368) \u2014 Medium Severity - Web Hosting and IT Consultancy Services","og_description":"A notable security flaw, identified as CVE-2019-25368, has been discovered in OPNsense 19.1. This vulnerability involves multiple Cross-Site Scripting (XSS) issues that could allow an attacker to inject harmful code into your system. For users managing OPNsense installations, understanding this vulnerability and applying necessary updates is crucial for maintaining a secure network environment. Cross-Site Scripting, [&hellip;]","og_url":"https:\/\/www.ucartz.com\/updates\/opnsense-cross-site-scripting-vulnerability-cve-2019-25368-medium-severity\/","og_site_name":"Web Hosting and IT Consultancy Services","article_published_time":"2026-02-18T20:01:21+00:00","author":"Alex Joseph","twitter_card":"summary_large_image","twitter_misc":{"Written by":"Alex Joseph","Est. reading time":"2 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/www.ucartz.com\/updates\/opnsense-cross-site-scripting-vulnerability-cve-2019-25368-medium-severity\/#article","isPartOf":{"@id":"https:\/\/www.ucartz.com\/updates\/opnsense-cross-site-scripting-vulnerability-cve-2019-25368-medium-severity\/"},"author":{"name":"Alex Joseph","@id":"https:\/\/www.ucartz.com\/updates\/#\/schema\/person\/1ba9bfab02a76dee216c9f55bb634e56"},"headline":"OPNsense Cross-Site Scripting Vulnerability (CVE-2019-25368) \u2014 Medium Severity","datePublished":"2026-02-18T20:01:21+00:00","mainEntityOfPage":{"@id":"https:\/\/www.ucartz.com\/updates\/opnsense-cross-site-scripting-vulnerability-cve-2019-25368-medium-severity\/"},"wordCount":417,"commentCount":0,"publisher":{"@id":"https:\/\/www.ucartz.com\/updates\/#organization"},"keywords":["Cross Site Scripting","Network Firewall","OPNsense","Web Security","Xss"],"articleSection":["Security"],"inLanguage":"en-US","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/www.ucartz.com\/updates\/opnsense-cross-site-scripting-vulnerability-cve-2019-25368-medium-severity\/#respond"]}]},{"@type":"WebPage","@id":"https:\/\/www.ucartz.com\/updates\/opnsense-cross-site-scripting-vulnerability-cve-2019-25368-medium-severity\/","url":"https:\/\/www.ucartz.com\/updates\/opnsense-cross-site-scripting-vulnerability-cve-2019-25368-medium-severity\/","name":"OPNsense Cross-Site Scripting Vulnerability (CVE-2019-25368) \u2014 Medium Severity - Web Hosting and IT Consultancy Services","isPartOf":{"@id":"https:\/\/www.ucartz.com\/updates\/#website"},"datePublished":"2026-02-18T20:01:21+00:00","breadcrumb":{"@id":"https:\/\/www.ucartz.com\/updates\/opnsense-cross-site-scripting-vulnerability-cve-2019-25368-medium-severity\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.ucartz.com\/updates\/opnsense-cross-site-scripting-vulnerability-cve-2019-25368-medium-severity\/"]}]},{"@type":"BreadcrumbList","@id":"https:\/\/www.ucartz.com\/updates\/opnsense-cross-site-scripting-vulnerability-cve-2019-25368-medium-severity\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.ucartz.com\/updates\/"},{"@type":"ListItem","position":2,"name":"OPNsense Cross-Site Scripting Vulnerability (CVE-2019-25368) \u2014 Medium Severity"}]},{"@type":"WebSite","@id":"https:\/\/www.ucartz.com\/updates\/#website","url":"https:\/\/www.ucartz.com\/updates\/","name":"Web Hosting and IT Consultancy Services","description":"Discover the Potential of Digital Transformation through Effortless Hosting and Professional IT Consulting!","publisher":{"@id":"https:\/\/www.ucartz.com\/updates\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.ucartz.com\/updates\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/www.ucartz.com\/updates\/#organization","name":"Web Hosting and IT Consultancy Services","url":"https:\/\/www.ucartz.com\/updates\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.ucartz.com\/updates\/#\/schema\/logo\/image\/","url":"https:\/\/www.ucartz.com\/updates\/wp-content\/uploads\/2025\/12\/ucartzLogo-1.png","contentUrl":"https:\/\/www.ucartz.com\/updates\/wp-content\/uploads\/2025\/12\/ucartzLogo-1.png","width":165,"height":50,"caption":"Web Hosting and IT Consultancy Services"},"image":{"@id":"https:\/\/www.ucartz.com\/updates\/#\/schema\/logo\/image\/"}},{"@type":"Person","@id":"https:\/\/www.ucartz.com\/updates\/#\/schema\/person\/1ba9bfab02a76dee216c9f55bb634e56","name":"Alex Joseph","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/0969fa5fefa2739cbd6fd5eaf04fed619e19f40d42e4a42650090606944ff747?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/0969fa5fefa2739cbd6fd5eaf04fed619e19f40d42e4a42650090606944ff747?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/0969fa5fefa2739cbd6fd5eaf04fed619e19f40d42e4a42650090606944ff747?s=96&d=mm&r=g","caption":"Alex Joseph"},"description":"Alex Joseph is a Senior Support Staff professional with deep experience in server management, web hosting technologies, and cybersecurity operations. He works daily with Linux servers, cloud platforms, performance tuning, and security hardening, giving him strong real-world technical knowledge. Along with his support role, he write about security best practices, hosting infrastructure, and software management.","url":"https:\/\/www.ucartz.com\/updates\/author\/alexjoseph\/"}]}},"_links":{"self":[{"href":"https:\/\/www.ucartz.com\/updates\/wp-json\/wp\/v2\/posts\/3367","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.ucartz.com\/updates\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.ucartz.com\/updates\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.ucartz.com\/updates\/wp-json\/wp\/v2\/users\/17"}],"replies":[{"embeddable":true,"href":"https:\/\/www.ucartz.com\/updates\/wp-json\/wp\/v2\/comments?post=3367"}],"version-history":[{"count":0,"href":"https:\/\/www.ucartz.com\/updates\/wp-json\/wp\/v2\/posts\/3367\/revisions"}],"wp:attachment":[{"href":"https:\/\/www.ucartz.com\/updates\/wp-json\/wp\/v2\/media?parent=3367"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.ucartz.com\/updates\/wp-json\/wp\/v2\/categories?post=3367"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.ucartz.com\/updates\/wp-json\/wp\/v2\/tags?post=3367"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}