CVE-2017-15941

Cross-site scripting (XSS) vulnerability in Palo Alto Networks PAN-OS before 6.1.19, 7.0.x before 7.0.19, 7.1.x before 7.1.14, and 8.0.x before 8.0.7, when the GlobalProtect gateway or portal is configured, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
Configurations

Configuration 1 (hide)

OR cpe:2.3:o:paloaltonetworks:pan-os:*:*:*:*:*:*:*:*
cpe:2.3:o:paloaltonetworks:pan-os:*:*:*:*:*:*:*:*
cpe:2.3:o:paloaltonetworks:pan-os:*:*:*:*:*:*:*:*
cpe:2.3:o:paloaltonetworks:pan-os:*:*:*:*:*:*:*:*

History

21 Nov 2024, 03:15

Type Values Removed Values Added
References () http://www.securityfocus.com/bid/102446 - Third Party Advisory, VDB Entry () http://www.securityfocus.com/bid/102446 - Third Party Advisory, VDB Entry
References () http://www.securitytracker.com/id/1040147 - Third Party Advisory, VDB Entry () http://www.securitytracker.com/id/1040147 - Third Party Advisory, VDB Entry
References () https://security.paloaltonetworks.com/CVE-2017-15941 - () https://security.paloaltonetworks.com/CVE-2017-15941 -

Information

Published : 2018-01-10 18:29

Updated : 2024-11-21 03:15


NVD link : CVE-2017-15941

Mitre link : CVE-2017-15941

CVE.ORG link : CVE-2017-15941


JSON object : View

Products Affected

paloaltonetworks

  • pan-os
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')