/usr/local/www/pkg.php in pfSense through 2.5.2 uses ...
        
  Critical severity
        
          Unreviewed
      
        Published
          Jan 27, 2022 
          to the GitHub Advisory Database
          •
          Updated Feb 3, 2023 
      
  
Description
        Published by the National Vulnerability Database
      Jan 26, 2022 
    
  
        Published to the GitHub Advisory Database
      Jan 27, 2022 
    
  
        Last updated
      Feb 3, 2023 
    
  
/usr/local/www/pkg.php in pfSense through 2.5.2 uses $_REQUEST['pkg_filter'] in a PHP echo call.
References