This exploit demonstrates multiple reflected and stored XSS vulnerabilities in pfSense 2.4.4-p1. It provides specific URLs, methods, parameters, and payloads to trigger XSS alerts.
Classification
Working Poc 95%
Attack Type
Xss
Complexity
Trivial
Reliability
Reliable
Target:pfSense 2.4.4-p1
Auth required
Prerequisites:Access to the pfSense web interface · Valid credentials for authenticated endpoints