First published: Wed May 10 2023(Updated: )
A cross-site scripting (XSS) vulnerability in Palo Alto Networks PAN-OS software on Panorama appliances enables an authenticated read-write administrator to store a JavaScript payload in the web interface that will execute in the context of another administrator’s browser when viewed.
Credit: psirt@paloaltonetworks.com
Affected Software | Affected Version | How to fix |
---|---|---|
Paloaltonetworks Pan-os | >=8.1.0<8.1.25 | |
Paloaltonetworks Pan-os | >=9.0.0<9.0.17 | |
Paloaltonetworks Pan-os | >=9.1.0<9.1.16 | |
Paloaltonetworks Pan-os | >=10.0.0<10.0.7 | |
Paloaltonetworks Panorama M-200 | ||
Paloaltonetworks Panorama M-500 | ||
Paloaltonetworks Panorama M-600 |
This issue is fixed in PAN-OS 8.1.25, PAN-OS 9.0.17, PAN-OS 9.1.16, PAN-OS 10.0.7, and all later PAN-OS versions.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-0007 is a cross-site scripting (XSS) vulnerability in Palo Alto Networks PAN-OS software on Panorama appliances.
This vulnerability allows an authenticated read-write administrator to store a JavaScript payload in the web interface that will execute in the context of another administrator's browser when viewed.
The affected versions are PAN-OS 8.1.0 to 8.1.25, 9.0.0 to 9.0.17, 9.1.0 to 9.1.16, and 10.0.0 to 10.0.7.
The severity of CVE-2023-0007 is medium with a CVSS score of 4.8.
To fix this vulnerability, Palo Alto Networks recommends upgrading to a fixed software version. Please refer to the vendor's security advisory for more information.