Impact
Palo Alto Networks PAN‑OS software contains a stored XSS flaw that allows an authenticated administrator to embed malicious JavaScript via the web interface. Once stored, the payload executes in the browser of any user who views the affected page, creating opportunities for session hijacking, credential theft, or further lateral movement within the management console. The vulnerability is of moderate severity (CVSS 4.4) and requires legitimate administrative credentials to insert the payload, but once present it can affect any user who interacts with the compromised page.
Affected Systems
PAN‑OS on PA‑Series and VM‑Series firewalls as well as Panorama (both virtual and M‑Series) are affected. The flaw applies to a range of release streams, including 12.1.5 through 12.1.6 and earlier patch levels of 12.1.x, all 11.2.x releases from 11.2.0 through the latest patched versions, all 11.1.x releases from 11.1.0 through the latest patched versions, and all 10.2.x releases from 10.2.0 through the latest patched versions. Older supported releases should also be upgraded to a fixed version. Cloud NGFW and Prisma Access are not impacted.
Risk and Exploitability
The CVSS score of 4.4 indicates moderate impact, and no EPSS score is available, suggesting a low probability of widespread exploitation. The vulnerability is not listed in CISA KEV, and no publicly known exploits are reported. Attack requires a valid PAN‑OS administrator account to place the malicious payload via the web interface. Once stored, any user who loads the affected page will execute the JavaScript in their browser, enabling an attacker to hijack sessions, steal credentials, or redirect traffic. Because privileged access is necessary to inject the payload, the risk is limited to administrators, but the potential impact on downstream users can be significant.
OpenCVE Enrichment