In pfSense CE /suricata/suricata_app_parsers.php, the value of the policy_name parameter is not sanitized of HTML-related strings/characters before being directly displayed. This can result in stored cross-site scripting. The attacker must be authenticated with at least "WebCfg - Services: suricata package" permissions.
                
            Metrics
Affected Vendors & Products
References
        History
                    Fri, 10 Oct 2025 18:45:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| First Time appeared | 
        
        Pfsense
         Pfsense pfsense  | 
|
| CPEs | cpe:2.3:a:pfsense:pfsense:*:*:*:*:community:*:*:* | |
| Vendors & Products | 
        
        Pfsense
         Pfsense pfsense  | 
|
| Metrics | 
        
        cvssV3_1
         
  | 
Wed, 17 Sep 2025 17:45:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| References | 
         | 
Thu, 11 Sep 2025 10:45:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| First Time appeared | 
        
        Netgate
         Netgate pfsense Ce  | 
|
| Vendors & Products | 
        
        Netgate
         Netgate pfsense Ce  | 
Wed, 10 Sep 2025 15:15:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| Metrics | 
        
        ssvc
         
  | 
Tue, 09 Sep 2025 20:45:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| Description | In pfSense CE /suricata/suricata_app_parsers.php, the value of the policy_name parameter is not sanitized of HTML-related strings/characters before being directly displayed. This can result in stored cross-site scripting. The attacker must be authenticated with at least "WebCfg - Services: suricata package" permissions. | |
| Title | Netgate pfSense CE Suricata package v7.0.8_2 Stored Cross-Site Scripting | |
| Weaknesses | CWE-79 | |
| References | 
         | |
| Metrics | 
        
        cvssV4_0
         
  | 
Status: PUBLISHED
Assigner: VulnCheck
Published: 2025-09-09T20:23:44.475Z
Updated: 2025-09-17T17:26:29.274Z
Reserved: 2025-04-15T19:15:22.567Z
Link: CVE-2025-34178
Updated: 2025-09-10T14:04:12.268Z
Status : Analyzed
Published: 2025-09-09T21:15:35.670
Modified: 2025-10-10T18:42:08.297
Link: CVE-2025-34178
No data.