First published: Tue Mar 26 2019(Updated: )
The Expedition Migration tool 1.1.8 and earlier may allow an authenticated attacker to run arbitrary JavaScript or HTML in the User Mapping Settings for account name of admin user.
Credit: psirt@paloaltonetworks.com psirt@paloaltonetworks.com
Affected Software | Affected Version | How to fix |
---|---|---|
Paloaltonetworks Expedition | <=1.1.8 | |
<=1.1.8 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-1569 has a high severity rating due to the potential for authenticated attackers to execute arbitrary JavaScript or HTML.
To fix CVE-2019-1569, upgrade the Expedition Migration tool to version 1.1.9 or later.
CVE-2019-1569 affects users of Expedition Migration tool versions 1.1.8 and earlier.
CVE-2019-1569 allows authenticated attackers to manipulate user mapping settings via arbitrary JavaScript or HTML code.
Yes, exploitation of CVE-2019-1569 requires an authenticated user to access the user mapping settings.