A DOM-Based cross-site scripting (XSS) vulnerability in Palo Alto Networks PAN-OS software enables a remote attacker to execute a JavaScript payload in the context of an administrator’s browser when they view a specifically crafted link to the PAN-OS web interface.
2023-12-13T19:15:09.030
2024-11-21T08:44:33.980
Modified
CVSSv3.1: 8.8 (HIGH)
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Operating System | paloaltonetworks | pan-os | < 8.1.25 | Yes |
Operating System | paloaltonetworks | pan-os | < 9.0.17 | Yes |
Operating System | paloaltonetworks | pan-os | < 9.1.16 | Yes |
Operating System | paloaltonetworks | pan-os | < 10.0.12 | Yes |
Operating System | paloaltonetworks | pan-os | < 10.1.9 | Yes |
Operating System | paloaltonetworks | pan-os | < 10.2.4 | Yes |
Operating System | paloaltonetworks | pan-os | 11.0.0 | Yes |