QID 730824
Date Published: 2023-06-14
QID 730824: Palo Alto Networks (PAN-OS)Stored Cross-Site Scripting (XSS) Vulnerability in the Panorama Web Interface (PAN-166872)
PAN OS is the software that runs all Palo Alto Networks next-generation firewalls.
A cross-site scripting (XSS) vulnerability in Palo Alto Networks PAN-OS software on Panorama appliances enables an authenticated read-write administrator to store a JavaScript payload in the web interface that will execute in the context of another administrators browser when viewed.
Affected Versions:
PAN-OS 8.1 versions earlier than PAN-OS 8.1.25 on Panorama
PAN-OS 9.0 versions earlier than PAN-OS 9.0.17 on Panorama
PAN-OS 9.1 versions earlier than PAN-OS 9.1.16 on Panorama
PAN-OS 10.0 versions earlier than PAN-OS 10.0.7 on Panorama
QID Detection Logic (Authenticated):
This QID looks for the vulnerable version of PAN-OS
NOTE: Detection is made potential because the signature doesn't check for the Workaround/Mitigations mentioned in the Palo Alto advisory.
A cross-site scripting (XSS) vulnerability in Palo Alto Networks PAN-OS software on Panorama appliances enables an authenticated read-write administrator to store a JavaScript payload in the web interface that will execute in the context of another administrators browser when viewed.
- PAN-166872 -
security.paloaltonetworks.com/CVE-2023-0007
CVEs related to QID 730824
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| PAN-166872 |
|