XSS Vulnerability in Netgate pfSense Product Leading to Security Risks
CVE-2024-54779

5.4MEDIUM

Key Information:

Vendor

Netgate

Status
Vendor
CVE Published:
14 May 2025

What is CVE-2024-54779?

Netgate pfSense CE, before the beta release of version 2.8.0, along with its Plus builds, is susceptible to a Cross Site Scripting (XSS) vulnerability located in the 'widgets/log.widget.php' file. An attacker can exploit this weakness to inject malicious scripts into web pages viewed by users, potentially leading to unauthorized actions and data breaches. It is crucial for users of pfSense to apply patches and monitor their systems for any signs of exploitation.

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.