Description
In pfSense CE /usr/local/www/haproxy/haproxy_stats.php, the value of the showsticktablecontent parameter is displayed after being read from HTTP GET requests. This can enable reflected cross-site scripting when the victim is authenticated.
Problem types
CWE-79 Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting')
Product status
0.63_10 (custom)
Credits
Alex Williams (Pellera Technologies)
References
github.com/...ommit/04d1328ab077830eb57a24bb7018c812b6358c64
redmine.pfsense.org/issues/16411
www.vulncheck.com/...gate-pf-sense-ce-ha-proxy-reflected-xss