CERT-In Vulnerability Note
CIVN-2023-0393
Cross site scripting vulnerability in Palo Alto software
Original Issue Date:December 29, 2023
Severity Rating: HIGH
Software Affected
Overview
A Vulnerability has been reported in Palo Alto Networks PAN-OS software which could allow a remote attacker to perform cross site scripting attack on an affected system.
Description
This Vulnerability exists in PAN-OS software due to improper validation of user supplied input. An attacker could exploit this vulnerability to execute a JavaScript payload in the context of an administrators browser when they view a specifically crafted link to the PAN-OS web interface.
Successful exploitation of this vulnerability could allow the attacker to steal the victim¿s cookie based authentication credentials.
Solution
Apply appropriate updates as mentioned in:
https://security.paloaltonetworks.com/CVE-2023-6790
Vendor Information
Palo Alto
https://security.paloaltonetworks.com/CVE-2023-6790
References
Palo Alto
https://security.paloaltonetworks.com/CVE-2023-6790
CVE Name
CVE-2023-6790
Disclaimer
The information provided herein is on "as is" basis, without warranty of any kind.
Contact Information
Email: info@cert-in.org.in Phone: +91-11-24368572
Postal address
Indian Computer Emergency Response Team (CERT-In) Ministry of Electronics and Information Technology Government of India Electronics Niketan 6, CGO Complex, Lodhi Road, New Delhi - 110 003 India
|