A cross-site scripting (XSS) vulnerability in Palo Alto Networks PAN-OS software on Panorama appliances enables an authenticated read-write administrator to store a JavaScript payload in the web interface that will execute in the context of another administrator’s browser when viewed.
2023-05-10T17:15:08.910
2024-11-21T07:36:22.863
Modified
CVSSv3.1: 6.5 (MEDIUM)
| Type | Vendor | Product | Version/Range | Vulnerable? |
|---|---|---|---|---|
| Operating System | paloaltonetworks | pan-os | < 8.1.25 | Yes |
| Operating System | paloaltonetworks | pan-os | < 9.0.17 | Yes |
| Operating System | paloaltonetworks | pan-os | < 9.1.16 | Yes |
| Operating System | paloaltonetworks | pan-os | < 10.0.7 | Yes |
| Hardware | paloaltonetworks | panorama_m-200 | - | No |
| Hardware | paloaltonetworks | panorama_m-500 | - | No |
| Hardware | paloaltonetworks | panorama_m-600 | - | No |