VYPR
Unrated severityNVD Advisory· Published Sep 9, 2025· Updated Nov 20, 2025

Netgate pfSense CE HAProxy Package 0.63_10 Reflected Cross-Site Scripting

CVE-2025-34172

Description

In pfSense CE /usr/local/www/haproxy/haproxy_stats.php, the value of the showsticktablecontent parameter is displayed after being read from HTTP GET requests. This can enable reflected cross-site scripting when the victim is authenticated.

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

3

News mentions

0

No linked articles in our index yet.