RULE(RULE ID:338489)

Rule General Information
Release Date: 2024-10-29
Rule Name: Pfsense Cross-Site Scripting Vulnerability (CVE-2024-46538)
Severity:
CVE ID:
Rule Protection Details
Description: A cross-site scripting (XSS) vulnerability in pfsense v2.5.2 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the $pconfig variable at interfaces_groups_edit.php.
Impact: An attacker can conduct a cross-site scripting attack to inject malicious client-side scripts into web pages viewed by other users, or to bypass access controls such as the same-origin policy, if affected version is installed.
Affected OS: Windows, Linux, Others
Reference: https://github.com/physicszq/web_issue/blob/main/pfsense/interfaces_groups_edit_file.md_xss.md
https://redmine.pfsense.org/issues/15778
Solutions
Please refer to announcements or patches release by the vendor: https://redmine.pfsense.org/issues/15778