CVE-2024-46538
PoC largeCross-Site Scripting (XSS) in pfSense interfaces_groups_edit.php
pfSense 2.5.2 contains a cross-site scripting flaw (CWE-79) in the web UI script interfaces_groups_edit.php, where a crafted payload injected into the $pconfig parameter is rendered without proper sanitization. An attacker who can submit the crafted input — the CVSS vector requires highly privileged (admin-level) access — can cause arbitrary web scripts or HTML to execute in the browser of a user viewing the affected page. Successful execution in an administrator's session could allow session hijacking, unauthorized configuration changes, or theft of credentials, with scope changed (S:C) meaning the script can cross the security boundary of the vulnerable component. Affected users are administrators and organizations running pfSense 2.5.2 from Netgate. Exploitation has not been confirmed in the wild and the flaw is not in CISA KEV, but a public proof of concept exists and EPSS puts the 30-day exploitation probability at 81.6% (top percentile), so exploitation activity is considered likely.
What to do: Organizations running pfSense 2.5.2 should upgrade to the latest pfSense release available from Netgate and verify the fixed version in Netgate's advisories, since the CVE data does not specify one. Until then, restrict web UI access to trusted management networks or VPN, limit the number of admin accounts (exploitation requires admin-level privileges), and inspect saved interface group configuration for unexpected injected HTML or script content. Check access logs for requests to interfaces_groups_edit.php as an indicator of probing.
| Netgate pfSense | 2.5.2 (as reported in the CVE; the data does not confirm which other versions are affected or the fixed version) |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
A cross-site scripting (XSS) vulnerability in pfsense v2.5.2 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the $pconfig variable at interfaces_groups_edit.php.
- Vendors
- netgate
- Products
- pfsense
- Weakness
- CWE-79
- Vector
- CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N
In the news0 stories
No ingested article mentions this CVE yet.