CVE-2019-16667 | pfSense 2.4.4-p3 diag_command.php csrf_callback txtCommand/txtRecallBuffer cross-site request forgery (ID 158614 / EDB-48714)
A vulnerability marked as problematic has been reported in pfSense 2.4.4-p3. This issue affects the function csrf_callback of the file diag_command.php. Performing manipulation of the argument txtCommand/txtRecallBuffer results in cross-site request forgery.
This vulnerability is reported as CVE-2019-16667. The attack is possible to be carried out remotely. Moreover, an exploit is present.