A cross-site scripting (XSS) vulnerability in Palo Alto Networks PAN-OS software on Panorama appliances enables an authenticated read-write administrator to store a JavaScript payload in the web interface that will execute in the context of another administrator’s browser when viewed.
2023-05-10T17:15:08.910
2024-11-21T07:36:22.863
Modified
CVSSv3.1: 6.5 (MEDIUM)
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Operating System | paloaltonetworks | pan-os | < 8.1.25 | Yes |
Operating System | paloaltonetworks | pan-os | < 9.0.17 | Yes |
Operating System | paloaltonetworks | pan-os | < 9.1.16 | Yes |
Operating System | paloaltonetworks | pan-os | < 10.0.7 | Yes |
Hardware | paloaltonetworks | panorama_m-200 | - | No |
Hardware | paloaltonetworks | panorama_m-500 | - | No |
Hardware | paloaltonetworks | panorama_m-600 | - | No |