Get supportSecurity advisories
Subscriptions
Report vulnerabilities
Palo Alto Networks Security Advisories / CVE-2019-1567

CVE-2019-1567 Stored Cross-Site Scripting in Expedition Migration Tool


Severity 5.4 · MEDIUM
Attack Vector NETWORK
Attack Complexity LOW
Privileges Required LOW
User Interaction REQUIRED
Scope CHANGED
Confidentiality Impact LOW
Integrity Impact LOW
Availability Impact NONE
NVD JSON
Published: 2019-02-28
Updated: 2019-02-28
Ref#: MT-908 PAN-SA-2019-0003

Description

A stored cross-site scripting (XSS) vulnerability exists in the Palo Alto Networks Migration Tool (“Expedition”). (Ref # MT-908/ CVE-2019-1567)

Successful exploitation of this issue may allow an authenticated attacker to inject arbitrary JavaScript or HTML in the User Mapping Settings.

This issue affects Expedition 1.1.6 and earlier

Product Status

Expedition

VersionsAffectedUnaffected
1.1<= 1.1.6>= 1.1.7

Severity: MEDIUM

CVSSv3.1 Base Score: 5.4 ( CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N )

Solution

Expedition 1.1.7 and later

Workarounds and Mitigations

N/A

Acknowledgements

  • Palo Alto Networks would like to thank Sayali Kulkarni of Tenable for reporting this issue.
© 2020 Palo Alto Networks, Inc. All rights reserved.