CVE-2023-6790
13.12.2023, 19:15
A DOM-Based cross-site scripting (XSS) vulnerability in Palo Alto Networks PAN-OS software enables a remote attacker to execute a JavaScript payload in the context of an administrators browser when they view a specifically crafted link to the PAN-OS web interface.
Vendor | Product | Version |
---|---|---|
paloaltonetworks | pan-os | 8.1.0 ≤ 𝑥 < 8.1.25 |
paloaltonetworks | pan-os | 9.0.0 ≤ 𝑥 < 9.0.17 |
paloaltonetworks | pan-os | 9.1.0 ≤ 𝑥 < 9.1.16 |
paloaltonetworks | pan-os | 10.0.0 ≤ 𝑥 < 10.0.12 |
paloaltonetworks | pan-os | 10.1.0 ≤ 𝑥 < 10.1.9 |
paloaltonetworks | pan-os | 10.2.0 ≤ 𝑥 < 10.2.4 |
paloaltonetworks | pan-os | 11.0.0 |
𝑥
= Vulnerable software versions