Unrated severityNVD Advisory· Published Sep 9, 2025· Updated Nov 20, 2025
Netgate pfSense CE HAProxy Package 0.63_10 Reflected Cross-Site Scripting
CVE-2025-34172
Description
In pfSense CE /usr/local/www/haproxy/haproxy_stats.php, the value of the showsticktablecontent parameter is displayed after being read from HTTP GET requests. This can enable reflected cross-site scripting when the victim is authenticated.
Affected products
2- Netgate/pfSense CEv5Range: 0.63_10
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
3- github.com/pfsense/FreeBSD-ports/commit/04d1328ab077830eb57a24bb7018c812b6358c64mitrepatch
- www.vulncheck.com/advisories/netgate-pf-sense-ce-ha-proxy-reflected-xssmitrethird-party-advisory
- redmine.pfsense.org/issues/16411mitreissue-tracking
News mentions
0No linked articles in our index yet.