In pfSense CE /usr/local/www/haproxy/haproxy_stats.php, the value of the showsticktablecontent parameter is displayed after being read from HTTP GET requests. This can enable reflected cross-site scripting when the victim is authenticated.
                
            Metrics
Affected Vendors & Products
References
        History
                    Fri, 10 Oct 2025 19:00:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| First Time appeared | 
        
        Pfsense
         Pfsense pfsense  | 
|
| CPEs | cpe:2.3:a:pfsense:pfsense:*:*:*:*:community:*:*:* | |
| Vendors & Products | 
        
        Pfsense
         Pfsense pfsense  | 
|
| Metrics | 
        
        cvssV3_1
         
  | 
Wed, 17 Sep 2025 17:30:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| References | 
         | 
Thu, 11 Sep 2025 10:45:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| First Time appeared | 
        
        Netgate
         Netgate pfsense Ce  | 
|
| Vendors & Products | 
        
        Netgate
         Netgate pfsense Ce  | 
Wed, 10 Sep 2025 14:15:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| Metrics | 
        
        ssvc
         
  | 
Tue, 09 Sep 2025 19:45:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| Description | In pfSense CE /usr/local/www/haproxy/haproxy_stats.php, the value of the showsticktablecontent parameter is displayed after being read from HTTP GET requests. This can enable reflected cross-site scripting when the victim is authenticated. | |
| Title | Netgate pfSense CE HAProxy Package 0.63_10 Reflected Cross-Site Scripting | |
| Weaknesses | CWE-79 | |
| References | 
         | |
| Metrics | 
        
        cvssV4_0
         
  | 
Status: PUBLISHED
Assigner: VulnCheck
Published: 2025-09-09T19:43:30.508Z
Updated: 2025-09-17T17:15:06.110Z
Reserved: 2025-04-15T19:15:22.567Z
Link: CVE-2025-34172
Updated: 2025-09-10T13:54:54.697Z
Status : Analyzed
Published: 2025-09-09T20:15:37.870
Modified: 2025-10-10T18:47:46.710
Link: CVE-2025-34172
No data.