First published: Tue Apr 09 2019(Updated: )
The Expedition Migration tool 1.1.6 and earlier may allow an authenticated attacker to run arbitrary JavaScript or HTML in the User Mapping Settings.
Credit: psirt@paloaltonetworks.com psirt@paloaltonetworks.com
Affected Software | Affected Version | How to fix |
---|---|---|
Paloaltonetworks Expedition Migration Tool | <=1.1.6 | |
<=1.1.6 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-1567 is classified as a medium severity vulnerability.
To fix CVE-2019-1567, upgrade the Expedition Migration tool to version 1.1.7 or later.
CVE-2019-1567 affects users of Expedition Migration tool versions 1.1.6 and earlier.
CVE-2019-1567 allows an authenticated attacker to run arbitrary JavaScript or HTML code.
Yes, exploitation of CVE-2019-1567 requires authentication to the Expedition Migration tool.