Palo Alto Networks Expedition Migration Tool CVE-2019-1567 HTML Injection Vulnerability
BID:107216
Info
Palo Alto Networks Expedition Migration Tool CVE-2019-1567 HTML Injection Vulnerability
| Bugtraq ID: | 107216 |
| Class: | Input Validation Error |
| CVE: |
CVE-2019-1567 |
| Remote: | Yes |
| Local: | No |
| Published: | Feb 28 2019 12:00AM |
| Updated: | Feb 28 2019 12:00AM |
| Credit: | Sayali Kulkarni from Tenable. |
| Vulnerable: |
Paloaltonetworks Expedition (Migration Tool) 1.1.6 Paloaltonetworks Expedition (Migration Tool) 1.1.5 Paloaltonetworks Expedition (Migration Tool) 1.1.4 Paloaltonetworks Expedition (Migration Tool) 1.1.3 Paloaltonetworks Expedition (Migration Tool) 1.1.2 Paloaltonetworks Expedition (Migration Tool) 1.1.1 Paloaltonetworks Expedition (Migration Tool) 1.1 |
| Not Vulnerable: |
Paloaltonetworks Expedition (Migration Tool) 1.1.7 |
Discussion
Palo Alto Networks Expedition Migration Tool CVE-2019-1567 HTML Injection Vulnerability
Palo Alto Networks Expedition Migration Tool is prone to an HTML-injection vulnerability because it fails to properly sanitize user-supplied input.
Successful exploits will result in the execution of arbitrary attacker-supplied HTML and script code in the context of the affected application, potentially allowing the attacker to steal cookie-based authentication credentials or control how the page is rendered to the user. Other attacks are also possible.
Palo Alto Networks Expedition Migration Tool version 1.1.6 and prior are vulnerable.
Palo Alto Networks Expedition Migration Tool is prone to an HTML-injection vulnerability because it fails to properly sanitize user-supplied input.
Successful exploits will result in the execution of arbitrary attacker-supplied HTML and script code in the context of the affected application, potentially allowing the attacker to steal cookie-based authentication credentials or control how the page is rendered to the user. Other attacks are also possible.
Palo Alto Networks Expedition Migration Tool version 1.1.6 and prior are vulnerable.
Exploit / POC
Palo Alto Networks Expedition Migration Tool CVE-2019-1567 HTML Injection Vulnerability
Currently, we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently, we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
Palo Alto Networks Expedition Migration Tool CVE-2019-1567 HTML Injection Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
Palo Alto Networks Expedition Migration Tool CVE-2019-1567 HTML Injection Vulnerability
References:
References:
- Palo Alto Networks Homepage (Palo Alto Networks)
- Stored Cross-Site Scripting in Expedition Migration Tool (PAN-SA-2019-0003) (Palo Alto)