First published: Thu May 09 2019(Updated: )
Cross-site scripting (XSS) vulnerability in Palo Alto Networks Demisto 4.5 build 40249 may allow an unauthenticated attacker to run arbitrary JavaScript or HTML.
Credit: psirt@paloaltonetworks.com
Affected Software | Affected Version | How to fix |
---|---|---|
Paloaltonetworks Demisto | =4.5-40249 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-1568 is classified as a medium severity Cross-Site Scripting (XSS) vulnerability.
To fix CVE-2019-1568, update Palo Alto Networks Demisto to a patched version where the vulnerability is resolved.
CVE-2019-1568 affects users running Palo Alto Networks Demisto version 4.5 build 40249.
Yes, CVE-2019-1568 can be exploited by unauthenticated attackers to execute arbitrary JavaScript or HTML.
The potential impact of CVE-2019-1568 includes unauthorized access and control over user sessions leading to data theft.