Unrated severityNVD Advisory· Published Apr 10, 2015· Updated Jun 17, 2026
CVE-2015-2295
CVE-2015-2295
Description
Cross-site request forgery (CSRF) vulnerability in system_firmware_restorefullbackup.php in the WebGUI in pfSense before 2.2.1 allows remote attackers to hijack the authentication of administrators for requests that delete arbitrary files via the deletefile parameter.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
2Patches
Vulnerability mechanics
References
6- packetstormsecurity.com/files/131022/pfSense-2.2-Cross-Site-Request-Forgery-Cross-Site-Scripting.htmlnvdExploit
- www.htbridge.com/advisory/HTB23251nvdExploit
- www.securityfocus.com/archive/1/534987/100/0/threadednvd
- www.securityfocus.com/bid/73344nvd
- www.exploit-db.com/exploits/36506/nvd
- www.pfsense.org/security/advisories/pfSense-SA-15_04.webgui.ascnvd
News mentions
0No linked articles in our index yet.