In pfSense CE /usr/local/www/suricata/suricata_filecheck.php, the value of the filehash parameter is directly displayed without sanitizing for HTML-related characters/strings. This can result in reflected cross-site scripting if the victim is authenticated.
                
            Metrics
Affected Vendors & Products
References
        History
                    Fri, 10 Oct 2025 19:00:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| First Time appeared | 
        
        Pfsense
         Pfsense pfsense  | 
|
| CPEs | cpe:2.3:a:pfsense:pfsense:*:*:*:*:community:*:*:* | |
| Vendors & Products | 
        
        Pfsense
         Pfsense pfsense  | 
|
| Metrics | 
        
        cvssV3_1
         
  | 
Wed, 17 Sep 2025 17:30:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| References | 
         | 
Thu, 11 Sep 2025 10:45:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| First Time appeared | 
        
        Netgate
         Netgate pfsense Ce  | 
|
| Vendors & Products | 
        
        Netgate
         Netgate pfsense Ce  | 
Tue, 09 Sep 2025 23:15:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| Metrics | 
        
        ssvc
         
  | 
Tue, 09 Sep 2025 20:15:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| Description | In pfSense CE /usr/local/www/suricata/suricata_filecheck.php, the value of the filehash parameter is directly displayed without sanitizing for HTML-related characters/strings. This can result in reflected cross-site scripting if the victim is authenticated. | |
| Title | Netgate pfSense CE Suricata package v7.0.8_2 Reflected Cross-Site Scripting | |
| Weaknesses | CWE-79 | |
| References | 
         | |
| Metrics | 
        
        cvssV4_0
         
  | 
Status: PUBLISHED
Assigner: VulnCheck
Published: 2025-09-09T20:09:50.289Z
Updated: 2025-09-17T17:22:11.125Z
Reserved: 2025-04-15T19:15:22.567Z
Link: CVE-2025-34175
Updated: 2025-09-09T20:22:25.521Z
Status : Analyzed
Published: 2025-09-09T20:15:38.903
Modified: 2025-10-10T18:46:41.620
Link: CVE-2025-34175
No data.