XSS Vulnerability in Netgate pfSense Product Leading to Security Risks
CVE-2024-54779
5.4MEDIUM
What is CVE-2024-54779?
Netgate pfSense CE, before the beta release of version 2.8.0, along with its Plus builds, is susceptible to a Cross Site Scripting (XSS) vulnerability located in the 'widgets/log.widget.php' file. An attacker can exploit this weakness to inject malicious scripts into web pages viewed by users, potentially leading to unauthorized actions and data breaches. It is crucial for users of pfSense to apply patches and monitor their systems for any signs of exploitation.