First published: Wed May 14 2025(Updated: )
Netgate pfSense CE (prior to 2.8.0 beta release) and corresponding Plus builds is vulnerable to Cross Site Scripting (XSS) in widgets/log.widget.php.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Netgate pfSense Community Edition | <2.8.0 | |
pfSense Plus | <2.8.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-54779 is classified as a Medium severity vulnerability due to its potential for Cross Site Scripting (XSS) attacks.
To mitigate CVE-2024-54779, users should upgrade to pfSense CE version 2.8.0 beta or later, or pfSense Plus version 2.8.0 or later.
CVE-2024-54779 affects Netgate pfSense CE versions prior to 2.8.0 beta and Netgate pfSense Plus versions prior to 2.8.0.
In the context of CVE-2024-54779, XSS allows attackers to inject malicious scripts into the web application, potentially compromising user data.
Users can identify their vulnerability to CVE-2024-54779 by checking their pfSense version against the affected releases before upgrading.