PAN-SA-2016-0031MediumDisclosed before NVD

PAN-SA-2016-0031 Cross-Site Scripting in Web Interface

Published
October 18, 2016
Last Modified
October 18, 2016

📋 Description

The Palo Alto Networks web management interface is vulnerable to a post-authentication persistent cross-site scripting condition in the monitor tab. (Ref # PAN-57659/95895). This issue affects the management interface of the device, where an authenticated administrator could inject malicious JavaScript into the web interface. This issue affects PAN-OS 5.0.19 and earlier; PAN-OS 5.1.12 and earlier; PAN-OS 6.0.14 and earlier; PAN-OS 6.1.13 and earlier; PAN-OS 7.0.9 and earlier; PAN-OS 7.1.4 and earlier

🎯 Affected products1

  • PAN-OS

✅ Remediation

PAN-OS 5.0.20 and later; PAN-OS 5.1.13 and later; PAN-OS 6.0.15 and later; PAN-OS 6.1.14 and later; PAN-OS 7.0.10 and later; PAN-OS 7.1.5 and later Workarounds and mitigations: N/A

🔗 References (1)