Palo Alto Networks MineMeld CVE-2019-1578 Cross Site Scripting Vulnerability
BID:109056
CVE-2019-1578 |Info
Palo Alto Networks MineMeld CVE-2019-1578 Cross Site Scripting Vulnerability
| Bugtraq ID: | 109056 |
| Class: | Input Validation Error |
| CVE: |
CVE-2019-1578 |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 27 2019 12:00AM |
| Updated: | Jun 27 2019 12:00AM |
| Credit: | Netskope and Veracode |
| Vulnerable: |
Paloaltonetworks MineMeld 0.9.60 |
| Not Vulnerable: |
Paloaltonetworks MineMeld 0.9.62 |
Discussion
Palo Alto Networks MineMeld CVE-2019-1578 Cross Site Scripting Vulnerability
Palo Alto Networks MineMeld is prone to an cross-site scripting vulnerability.
An attacker may leverage this issue to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may allow the attacker to steal cookie-based authentication credentials and launch other attacks.
Palo Alto Networks MineMeld 0.9.60 and prior are vulnerable; other versions may also be affected.
Palo Alto Networks MineMeld is prone to an cross-site scripting vulnerability.
An attacker may leverage this issue to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may allow the attacker to steal cookie-based authentication credentials and launch other attacks.
Palo Alto Networks MineMeld 0.9.60 and prior are vulnerable; other versions may also be affected.