CVE-2023-0007: PAN-OS: Stored Cross-Site Scripting (XSS) Vulnerability in the Panorama Web Interface
A cross-site scripting (XSS) vulnerability in Palo Alto Networks PAN-OS software on Panorama appliances enables an authenticated read-write administrator to store a JavaScript payload in the web interface that will execute in the context of another administrator’s browser when viewed.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is CVE-2023-0007?
CVE-2023-0007 is a cross-site scripting (XSS) vulnerability in Palo Alto Networks PAN-OS software on Panorama appliances.
How does CVE-2023-0007 work?
This vulnerability allows an authenticated read-write administrator to store a JavaScript payload in the web interface that will execute in the context of another administrator's browser when viewed.
Which versions of Palo Alto Networks PAN-OS software on Panorama appliances are affected?
The affected versions are PAN-OS 8.1.0 to 8.1.25, 9.0.0 to 9.0.17, 9.1.0 to 9.1.16, and 10.0.0 to 10.0.7.
What is the severity of CVE-2023-0007?
The severity of CVE-2023-0007 is medium with a CVSS score of 4.8.
How can I fix CVE-2023-0007?
To fix this vulnerability, Palo Alto Networks recommends upgrading to a fixed software version. Please refer to the vendor's security advisory for more information.