Reflected Cross-Site Scripting in pfSense CE by Netgate
CVE-2025-34175
5.1MEDIUM
What is CVE-2025-34175?
In pfSense CE, the script located at /usr/local/www/suricata/suricata_filecheck.php fails to sanitize the 'filehash' parameter properly. This oversight allows attackers to inject HTML-related characters, leading to reflected cross-site scripting attacks when an authenticated user accesses the compromised content. Such vulnerabilities can undermine user trust and expose sensitive data.
Affected Version(s)
pfSense CE 7.0.8_2