CVE-2024-0011

A reflected cross-site scripting (XSS) vulnerability in the Captive Portal feature of Palo Alto Networks PAN-OS software enables execution of malicious JavaScript (in the context of an authenticated Captive Portal user’s browser) if a user clicks on a malicious link, allowing phishing attacks that could lead to credential theft.
Configurations

Configuration 1 (hide)

OR cpe:2.3:o:paloaltonetworks:pan-os:*:*:*:*:*:*:*:*
cpe:2.3:o:paloaltonetworks:pan-os:*:*:*:*:*:*:*:*
cpe:2.3:o:paloaltonetworks:pan-os:*:*:*:*:*:*:*:*
cpe:2.3:o:paloaltonetworks:pan-os:*:*:*:*:*:*:*:*
cpe:2.3:o:paloaltonetworks:pan-os:*:*:*:*:*:*:*:*

History

09 Dec 2024, 15:05

Type Values Removed Values Added
CPE cpe:2.3:o:paloaltonetworks:pan-os:*:*:*:*:*:*:*:*
References () https://security.paloaltonetworks.com/CVE-2024-0011 - () https://security.paloaltonetworks.com/CVE-2024-0011 - Vendor Advisory
First Time Paloaltonetworks
Paloaltonetworks pan-os

21 Nov 2024, 08:45

Type Values Removed Values Added
References () https://security.paloaltonetworks.com/CVE-2024-0011 - () https://security.paloaltonetworks.com/CVE-2024-0011 -
Summary
  • (es) Una vulnerabilidad de Cross-Site Scripting (XSS) reflejado en la función Portal cautivo del software PAN-OS de Palo Alto Networks permite la ejecución de JavaScript malicioso (en el contexto del navegador de un usuario autenticado del Portal cautivo) si un usuario hace clic en un enlace malicioso, lo que permite Ataques de phishing que podrían conducir al robo de credenciales.

14 Feb 2024, 18:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-02-14 18:15

Updated : 2024-12-09 15:05


NVD link : CVE-2024-0011

Mitre link : CVE-2024-0011

CVE.ORG link : CVE-2024-0011


JSON object : View

Products Affected

paloaltonetworks

  • pan-os
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')