CVE-2024-46538 is a cross-site scripting (XSS) vulnerability affecting pfSense v2.5.2, allowing attackers to inject malicious web scripts or HTML via the $pconfig variable in interfaces_groups_edit.php. This vulnerability has a CVSS score of 4.8 (MEDIUM), indicating that a highly privileged attacker can achieve low impact on confidentiality and integrity with user interaction. While there is no confirmed active exploitation, a Proof-of-Concept (PoC) exploit has been published on GitHub, and the vulnerability has garnered significant community discussion with 11 mentions. There are currently no Metasploit, Nuclei, or ExploitDB modules available, and it is not listed in CISA's KEV catalog.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
2.5.2CPE matchmatch criteria | cpe:2.3:a:netgate:pfsense:2.5.2:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.