Back

MEDIUM

PAN-OS: Reflected Cross-Site Scripting (XSS) Vulnerability in GlobalProtect Portal

Published Feb 14, 2024

Description

A reflected cross-site scripting (XSS) vulnerability in the GlobalProtect portal feature of Palo Alto Networks PAN-OS software enables execution of malicious JavaScript (in the context of a user’s browser) if a user clicks on a malicious link, allowing phishing attacks that could lead to credential theft.

Affected products

Remediation

Vendor solution

This issue is fixed in PAN-OS 9.0.17-h4, PAN-OS 9.1.17, PAN-OS 10.1.11-h1, PAN-OS 10.1.12, and all later PAN-OS versions.

Metrics

References (1)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner palo_alto
Published Feb 14, 2024
Updated Apr 24, 2025
Reserved Nov 9, 2023
CISA Vulnrichment
Updated Feb 15, 2024
NVD
Status Analyzed
Modified Jun 17, 2026
Red Hat
Severity n/a
Public date n/a