Lucene search

K
nvd[email protected]NVD:CVE-2023-6789
HistoryDec 13, 2023 - 7:15 p.m.

CVE-2023-6789

2023-12-1319:15:08
CWE-79
web.nvd.nist.gov
palo alto networks
xss
vulnerability
authenticated
administrator
javascript
execution

4.8 Medium

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

HIGH

User Interaction

REQUIRED

Scope

CHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N

0.0004 Low

EPSS

Percentile

14.0%

A cross-site scripting (XSS) vulnerability in Palo Alto Networks PAN-OS software enables a malicious authenticated read-write administrator to store a JavaScript payload using the web interface. Then, when viewed by a properly authenticated administrator, the JavaScript payload executes and disguises all associated actions as performed by that unsuspecting authenticated administrator.

Affected configurations

NVD
Node
paloaltonetworkspan-osRange8.1.08.1.26
OR
paloaltonetworkspan-osRange9.0.09.0.17
OR
paloaltonetworkspan-osRange9.1.09.1.17
OR
paloaltonetworkspan-osRange10.1.010.1.11
OR
paloaltonetworkspan-osRange10.2.010.2.5
OR
paloaltonetworkspan-osRange11.0.011.0.2

4.8 Medium

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

HIGH

User Interaction

REQUIRED

Scope

CHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N

0.0004 Low

EPSS

Percentile

14.0%

Related for NVD:CVE-2023-6789