First published: Fri Oct 12 2018(Updated: )
GlobalProtect Portal Login page in Palo Alto Networks PAN-OS before 8.1.4 allows an unauthenticated attacker to inject arbitrary JavaScript or HTML.
Credit: psirt@paloaltonetworks.com
Affected Software | Affected Version | How to fix |
---|---|---|
Palo Alto Networks PAN-OS | <6.1.0 | |
Palo Alto Networks PAN-OS | >=7.0.0<=7.0.19 | |
Palo Alto Networks PAN-OS | >=8.1.0<8.1.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-10141 has a high severity rating due to its potential for arbitrary JavaScript or HTML injection.
To fix CVE-2018-10141, upgrade to PAN-OS version 8.1.4 or later.
CVE-2018-10141 affects PAN-OS versions prior to 8.1.4, including versions 6.1.x, 7.0.x, and 8.1.x up to 8.1.3.
Yes, CVE-2018-10141 is exploitable remotely as it allows unauthenticated attackers to inject code into the GlobalProtect Portal Login page.
An attacker can execute cross-site scripting (XSS) attacks using CVE-2018-10141, potentially compromising end-user sessions.