Palo Alto Networks PAN-OS < 5.0.16 / 6.0.x < 6.0.9 / 6.1.x < 6.1.3 XSS
Medium Nessus Plugin ID 83816
SynopsisThe remote host is affected by a cross-site scripting vulnerability.
DescriptionThe remote host is running a version of Palo Alto Networks PAN-OS prior to 5.0.16 / 6.0.9 / 6.1.3. It is, therefore, affected by a cross-site vulnerability in the management interface due to improper validation of user-supplied input. A remote attacker can exploit this vulnerability by convincing an authenticated administrator to use a specially crafted request, resulting in execution of arbitrary code in the context of the current user.
SolutionUpgrade to PAN-OS 5.0.16 / 6.0.9 / 6.1.13