CVE-2023-0010: PAN-OS: Reflected Cross-Site Scripting (XSS) Vulnerability in Captive Portal Authentication
A reflected cross-site scripting (XSS) vulnerability in the Captive Portal feature of Palo Alto Networks PAN-OS software can allow a JavaScript payload to be executed in the context of an authenticated Captive Portal user’s browser when they click on a specifically crafted link.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is CVE-2023-0010?
CVE-2023-0010 is a reflected cross-site scripting (XSS) vulnerability in the Captive Portal feature of Palo Alto Networks PAN-OS software.
How does CVE-2023-0010 affect Palo Alto Networks PAN-OS software?
CVE-2023-0010 allows a JavaScript payload to be executed in the context of an authenticated Captive Portal user's browser when they click on a specifically crafted link.
What version of Palo Alto Networks PAN-OS software are affected by CVE-2023-0010?
Palo Alto Networks PAN-OS software versions 8.1.0 to 8.1.24, 9.0.0 to 9.0.17, 9.1.0 to 9.1.16, 10.0.0 to 10.0.11, 10.1.0 to 10.1.6, and 10.2.0 to 10.2.2 are affected by CVE-2023-0010.
What is the severity of CVE-2023-0010?
CVE-2023-0010 has a severity rating of 5.4 (medium).
How can I find more information about CVE-2023-0010?
You can find more information about CVE-2023-0010 on the Palo Alto Networks website: https://security.paloaltonetworks.com/CVE-2023-0010.