Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2023-0010


A reflected cross-site scripting (XSS) vulnerability in the Captive Portal feature of Palo Alto Networks PAN-OS software can allow a JavaScript payload to be executed in the context of an authenticated Captive Portal user’s browser when they click on a specifically crafted link.


Published

2023-06-14T17:15:09.127

Last Modified

2024-11-21T07:36:23.227

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 5.4 (MEDIUM)

Weaknesses
  • Type: Secondary
    CWE-79
  • Type: Primary
    CWE-79

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Operating System paloaltonetworks pan-os ≤ 8.1.24 Yes
Operating System paloaltonetworks pan-os ≤ 9.0.17 Yes
Operating System paloaltonetworks pan-os ≤ 9.1.16 Yes
Operating System paloaltonetworks pan-os ≤ 10.0.11 Yes
Operating System paloaltonetworks pan-os ≤ 10.1.6 Yes
Operating System paloaltonetworks pan-os ≤ 10.2.2 Yes

References