CVE
CVE-2025-34172
In pfSense CE /usr/local/www/haproxy/haproxy_stats.php, the value of the showsticktablecontent parameter is displayed after being read from HTTP GET requests. This can enable reflected cross-site scripting when the victim is authenticated.
- Severity
- MEDIUM
- CVSS
- 4.8
- Published
- Modified
Linked Releases
| Distribution | Release | Status | Evidence |
|---|---|---|---|
| pfSense CE | 2.6.0 amd64 ce iso | unknown | source |
| pfSense CE | 2.6.0 amd64 ce memstick | unknown | source |
| pfSense CE | 2.6.0 amd64 ce memstick-adi | unknown | source |
| pfSense CE | 2.6.0 amd64 ce memstick-serial | unknown | source |