CVE-2024-54779: XSS
Netgate pfSense CE (prior to 2.8.0 beta release) and corresponding Plus builds is vulnerable to Cross Site Scripting (XSS) in widgets/log.widget.php.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-54779?
CVE-2024-54779 is classified as a Medium severity vulnerability due to its potential for Cross Site Scripting (XSS) attacks.
How do I fix CVE-2024-54779?
To mitigate CVE-2024-54779, users should upgrade to pfSense CE version 2.8.0 beta or later, or pfSense Plus version 2.8.0 or later.
What types of software are affected by CVE-2024-54779?
CVE-2024-54779 affects Netgate pfSense CE versions prior to 2.8.0 beta and Netgate pfSense Plus versions prior to 2.8.0.
What is Cross Site Scripting (XSS) in relation to CVE-2024-54779?
In the context of CVE-2024-54779, XSS allows attackers to inject malicious scripts into the web application, potentially compromising user data.
How can I identify if I am vulnerable to CVE-2024-54779?
Users can identify their vulnerability to CVE-2024-54779 by checking their pfSense version against the affected releases before upgrading.