PT-2024-6885 · Palo Alto Networks · Palo Alto Networks Expedition

Enrique Castillo

·

Published

2024-10-09

·

Updated

2024-11-16

·

CVE-2024-9467

CVSS v4.0

7.0

High

VectorAV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N/AU:N/R:U/V:C/RE:H/U:Amber
Name of the Vulnerable Software and Affected Versions Palo Alto Networks Expedition (affected versions not specified)
Description A reflected XSS issue in Palo Alto Networks Expedition allows the execution of malicious JavaScript in the context of an authenticated user's browser if they click on a malicious link. This enables phishing attacks that could lead to browser session theft. The vulnerability is related to the lack of protection of the web page structure, which can be exploited by a remote attacker to conduct cross-site scripting attacks by executing arbitrary JavaScript code and redirecting the user to an arbitrary URL.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

XSS

Weakness Enumeration

Related Identifiers

BDU:2024-08108
CVE-2024-9467

Affected Products

Palo Alto Networks Expedition