CVE-2025-34172 | Netgate pfSense CE 0.63_10 HTTP GET Request haproxy_stats.php showsticktablecontent cross site scripting (ID 16411)
A vulnerability, which was classified as problematic, has been found in Netgate pfSense CE 0.63_10. Affected by this vulnerability is an unknown functionality of the file /usr/local/www/haproxy/haproxy_stats.php of the component HTTP GET Request Handler. The manipulation of the argument showsticktablecontent leads to cross site scripting.
This vulnerability is referenced as CVE-2025-34172. Remote exploitation of the attack is possible. No exploit is available.
It is suggested to install a patch to address this issue.