CVE-2019-1578

Severity CVSS v4.0:
Pending analysis
Type:
CWE-79 Cross-Site Scripting (XSS)
Publication date:
01/07/2019
Last modified:
10/02/2020

Description

Cross-site scripting vulnerability in Palo Alto Networks MineMeld version 0.9.60 and earlier may allow a remote attacker able to convince an authenticated MineMeld admin to type malicious input in the MineMeld UI could execute arbitrary JavaScript code in the admin’s browser.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:paloaltonetworks:minemeld:*:*:*:*:*:*:*:* 0.9.60 (including)