CVE-2024-0007Cross-site Scripting in Palo Alto Networks Pan-os

Severity
4.8MEDIUMNVD
CNA6.8
EPSS
0.5%
top 32.64%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedFeb 14

Description

A cross-site scripting (XSS) vulnerability in Palo Alto Networks PAN-OS software enables a malicious authenticated read-write administrator to store a JavaScript payload using the web interface on Panorama appliances. This enables the impersonation of another authenticated administrator.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:NExploitability: 1.7 | Impact: 2.7

Affected Packages5 packages

NVDpaloaltonetworks/pan-os8.1.08.1.24+5
CVEListV5palo_alto_networks/pan-os8.18.1.24-h1+5
Palo Altopaloalto/pan-os

🔴Vulnerability Details

2
CVEList
PAN-OS: Stored Cross-Site Scripting (XSS) Vulnerability in the Panorama Web Interface2024-02-14
GHSA
GHSA-wm3v-gx9g-j79r: A cross-site scripting (XSS) vulnerability in Palo Alto Networks PAN-OS software enables a malicious authenticated read-write administrator to store a2024-02-14

📋Vendor Advisories

2
Palo Alto
PAN-OS: Stored Cross-Site Scripting (XSS) Vulnerability in the Panorama Web Interface2024-02-14
VMware
VMware Cloud Director updates address a partial information disclosure vulnerability (CVE-2024-22256).
CVE-2024-0007 — Cross-site Scripting in Palo | cvebase