CVE-2012-4043: XSS
Cross-site scripting (XSS) vulnerability in global-protect/login.esp in Palo Alto Networks Global Protect Portal, Global Protect Gateway, and SSL VPN portals 3.1.x through 3.1.11 and 4.0.x through 4.0.5 allows remote attackers to inject arbitrary web script or HTML via the inputStr parameter in a Login action.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2012-4043?
The severity of CVE-2012-4043 is classified as medium due to its ability to allow remote attackers to inject arbitrary web scripts or HTML.
How do I fix CVE-2012-4043?
To fix CVE-2012-4043, update affected Palo Alto Networks Global Protect Portal, Global Protect Gateway, and SSL VPN portals to the latest versions that address this vulnerability.
Which versions are affected by CVE-2012-4043?
CVE-2012-4043 affects Palo Alto Networks Global Protect Portal, Global Protect Gateway, and SSL VPN portals versions 3.1.x through 3.1.11 and 4.0.x through 4.0.5.
What is the impact of CVE-2012-4043?
The impact of CVE-2012-4043 includes potential unauthorized access and control by remote attackers through the injection of malicious scripts.
Who can exploit CVE-2012-4043?
CVE-2012-4043 can be exploited by remote attackers who can manipulate the inputStr parameter in the affected web applications.