VYPR
Medium severity5.4NVD Advisory· Published Sep 9, 2025· Updated Jul 14, 2026

CVE-2025-34178

CVE-2025-34178

Description

In pfSense CE /suricata/suricata_app_parsers.php, the value of the policy_name parameter is not sanitized of HTML-related strings/characters before being directly displayed. This can result in stored cross-site scripting. The attacker must be authenticated with at least "WebCfg - Services: suricata package" permissions.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

3
  • cpe:2.3:a:pfsense:pfsense:*:*:*:*:community:*:*:*
    Range: <2.8.0
  • Netgate/Pfsensellm-fuzzy2 versions
    (expand)+ 1 more
    • (no CPE)
    • (no CPE)range: 7.0.8_2

Patches

Vulnerability mechanics

References

3

News mentions

0

No linked articles in our index yet.