HTTP: Netgate pfSense Stored Cross-Site Scripting

This signature detects attempts to exploit a known vulnerability against Netgate pfSense. A successful attack can lead to Cross-Site Scripting attack.

Extended Description

pfSense CE through 2.6.0 and pfSense Plus before 22.05 allow XSS in the WebGUI via URL Table Alias URL parameters.

Affected Products

Netgate pfsense

Short Name
HTTP:XSS:NETGATE-PFSENSE-XSS
Severity
Minor
Recommended
False
Recommended Action
Drop
Category
HTTP
Keywords
CVE-2019-12347 CVE-2019-8953 CVE-2021-27933 CVE-2022-29273 CVE-2024-46538 CVE-2025-34172 Cross-Site Netgate Scripting Stored pfSense
Release Date
06/19/2019
Supported Platforms

srx-branch-12.3

srx-19.3

srx-branch-19.3

vsrx3bsd-19.2

srx-branch-19.4

vsrx-19.4

mx-12.3

mx-19.4

vmx-19.4

mx-19.3

vsrx3bsd-19.4

srx-19.4

vsrx-12.3

vmx-19.3

vsrx-19.2

srx-12.3

Sigpack Version
3866
False Positive
Unknown
Vendors

Netgate

CVSS Score

4.3

Found a potential security threat?