HTTP: Netgate pfSense Stored Cross-Site Scripting
This signature detects attempts to exploit a known vulnerability against Netgate pfSense. A successful attack can lead to Cross-Site Scripting attack.
Extended Description
pfSense CE through 2.6.0 and pfSense Plus before 22.05 allow XSS in the WebGUI via URL Table Alias URL parameters.
Affected Products
Netgate pfsense
References
CVE: CVE-2025-34172
URL: https://redmine.pfsense.org/issues/9554#change-40729 https://redmine.pfsense.org/issues/9335 https://docs.netgate.com/downloads/pfSense-SA-22_05.webgui.asc https://redmine.pfsense.org/issues/15778 https://github.com/physicszq/web_issue/blob/main/pfsense/interfaces_groups_edit_file.md_xss.md https://redmine.pfsense.org/issues/16411
srx-branch-12.3
srx-19.3
srx-branch-19.3
vsrx3bsd-19.2
srx-branch-19.4
vsrx-19.4
mx-12.3
mx-19.4
vmx-19.4
mx-19.3
vsrx3bsd-19.4
srx-19.4
vsrx-12.3
vmx-19.3
vsrx-19.2
srx-12.3
Netgate
4.3