CVE-2023-0007
Published: May 10, 2023
Modified: Jan 24, 2025
CVSS v3.1
6.5
Description
A cross-site scripting (XSS) vulnerability in Palo Alto Networks PAN-OS software on Panorama appliances enables an authenticated read-write administrator to store a JavaScript payload in the web interface that will execute in the context of another administrator’s browser when viewed.
| Vendor | Product | Versions |
|---|---|---|
Palo Alto Networks | PAN-OS | affected 10.0 - < 10.0.7affected 9.1 - < 9.1.16affected 9.0 - < 9.0.17affected 8.1 - < 8.1.25unaffected 10.1+2 more versions |
Palo Alto Networks | Prisma Access | unaffected All |
Palo Alto Networks | Cloud NGFW | unaffected All |
Weaknesses (CWE)
CVSS v3.1 Details
CVSS v3.1 Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now