CVE-2018-9337

Severity CVSS v4.0:
Pending analysis
Type:
CWE-79 Cross-Site Scripting (XSS)
Publication date:
03/07/2018
Last modified:
17/02/2020

Description

The PAN-OS web interface administration page in PAN-OS 6.1.20 and earlier, PAN-OS 7.1.17 and earlier, PAN-OS 8.0.10 and earlier, and PAN-OS 8.1.1 and earlier may allow an attacker to inject arbitrary JavaScript or HTML.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:paloaltonetworks:pan-os:*:*:*:*:*:*:*:* 6.0.0 (excluding) 6.1.20 (including)
cpe:2.3:o:paloaltonetworks:pan-os:*:*:*:*:*:*:*:* 7.1.0 (including) 7.1.17 (including)
cpe:2.3:o:paloaltonetworks:pan-os:*:*:*:*:*:*:*:* 8.0.0 (excluding) 8.0.10 (including)
cpe:2.3:o:paloaltonetworks:pan-os:*:*:*:*:*:*:*:* 8.1.0 (including) 8.1.1 (including)