Reflected Cross-Site Scripting Vulnerability in pfSense by Netgate
CVE-2025-34172
4.8MEDIUM
What is CVE-2025-34172?
The vulnerability found in pfSense CE allows an authenticated user to trigger a reflected cross-site scripting (XSS) attack through the 'showsticktablecontent' parameter in the haproxy_stats.php file. When this parameter is manipulated via HTTP GET requests, it can result in malicious scripts being executed in the context of the user's browser, potentially leading to unauthorized actions or data exposure. Users are advised to apply available patches to mitigate this security risk.
Affected Version(s)
pfSense CE 0.63_10