QID 731158
Date Published: 2024-02-20
QID 731158: Palo Alto Networks (PAN-OS) Stored Cross-Site Scripting (XSS) Vulnerability in the Panorama Web Interface (PAN-173112)
PAN-OS is the software that runs all Palo Alto Networks next-generation firewalls.
A cross-site scripting (XSS) vulnerability in Palo Alto Networks PAN-OS software enables a malicious authenticated read-write administrator to store a JavaScript payload using the web interface on Panorama appliances.
Affected Versions:
PAN-OS 10.1 versions earlier than PAN-OS 10.1.6
PAN-OS 10.0 versions earlier than PAN-OS 10.0.11
PAN-OS 9.1 versions earlier than PAN-OS 9.1.16
PAN-OS 9.0 versions earlier than PAN-OS 9.0.17
PAN-OS 8.1 versions earlier than PAN-OS 8.1.24-h1
QID Detection Logic (Authenticated):
This QID looks for the vulnerable version of PAN-OS.
NOTE: The QID marked as practice in this issue requires the attacker to have authenticated access to the PAN-OS web interface.
Successful exploitation of this vulnerability allows a malicious authenticated read-write administrator to store a JavaScript payload using the web interface on Panorama appliances.
- PAN-173112 -
security.paloaltonetworks.com/CVE-2024-0007
CVEs related to QID 731158
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| PAN-173112 |
|