First published: Tue Mar 26 2019(Updated: )
The Expedition Migration tool 1.1.8 and earlier may allow an authenticated attacker to run arbitrary JavaScript or HTML in the LDAP server settings.
Credit: psirt@paloaltonetworks.com psirt@paloaltonetworks.com
Affected Software | Affected Version | How to fix |
---|---|---|
Paloaltonetworks Expedition | <=1.1.8 | |
<=1.1.8 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-1570 has been categorized as a high severity vulnerability due to its potential to allow arbitrary JavaScript or HTML execution.
To remediate CVE-2019-1570, upgrade the Palo Alto Networks Expedition tool to a version later than 1.1.8.
CVE-2019-1570 affects users of Palo Alto Networks Expedition version 1.1.8 and earlier.
CVE-2019-1570 allows authenticated attackers to execute arbitrary scripts in the LDAP server settings, leading to potential data breaches.
CVE-2019-1570 requires authentication, meaning that only authenticated users can exploit the vulnerability.