CVE-2023-6789Cross-site Scripting in Palo Alto Networks Pan-os

Severity
4.8MEDIUMNVD
CNA4.3
EPSS
0.2%
top 62.72%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedDec 13
Latest updateDec 9

Description

A cross-site scripting (XSS) vulnerability in Palo Alto Networks PAN-OS software enables a malicious authenticated read-write administrator to store a JavaScript payload using the web interface. Then, when viewed by a properly authenticated administrator, the JavaScript payload executes and disguises all associated actions as performed by that unsuspecting authenticated administrator.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:NExploitability: 1.7 | Impact: 2.7

Affected Packages5 packages

NVDpaloaltonetworks/pan-os8.1.08.1.26+5
CVEListV5palo_alto_networks/pan-os8.18.1.26+6
Palo Altopaloalto/pan-os

🔴Vulnerability Details

3
OSV
btrfs: fix warning when putting transaction with qgroups enabled after abort2025-12-09
CVEList
PAN-OS: Stored Cross-Site Scripting (XSS) Vulnerability in the Web Interface2023-12-13
GHSA
GHSA-c7j9-rrpf-r62p: A cross-site scripting (XSS) vulnerability in Palo Alto Networks PAN-OS software enables a malicious authenticated read-write administrator to store a2023-12-13

📋Vendor Advisories

1
Palo Alto
PAN-OS: Stored Cross-Site Scripting (XSS) Vulnerability in the Web Interface2023-12-13
CVE-2023-6789 — Cross-site Scripting in Palo | cvebase