The Expedition Migration tool 1.1.8 and earlier may allow an authenticated attacker to run arbitrary JavaScript or HTML in the User Mapping Settings for account name of admin user.
[
{
"product": "Palo Alto Networks Expedition Migration Tool",
"vendor": "Palo Alto",
"versions": [
{
"status": "affected",
"version": "Expedition 1.1.8 and earlier"
}
]
}
]