CVE-2024-9467
Severity CVSS v4.0:
HIGH
Type:
CWE-79
Cross-Site Scripting (XSS)
Publication date:
09/10/2024
Last modified:
15/10/2024
Description
A reflected XSS vulnerability in Palo Alto Networks Expedition enables execution of malicious JavaScript in the context of an authenticated Expedition user's browser if that user clicks on a malicious link, allowing phishing attacks that could lead to Expedition browser session theft.
Impact
Base Score 4.0
7.00
Severity 4.0
HIGH
Base Score 3.x
6.10
Severity 3.x
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:paloaltonetworks:expedition:*:*:*:*:*:*:*:* | 1.2.0 (including) | 1.2.96 (excluding) |
To consult the complete list of CPE names with products and versions, see this page



