Expedition: Reflected Cross-Site Scripting Vulnerability Leads to Expedition Session Disclosure
Vulnerability Description
A reflected XSS vulnerability in Palo Alto Networks Expedition enables execution of malicious JavaScript in the context of an authenticated Expedition user's browser if that user clicks on a malicious link, allowing phishing attacks that could lead to Expedition browser session theft.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2024-9467
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- Enrique Castillo of Palo Alto Networks
More from Palo Alto Networks
View All →Affected Vendor
Palo Alto Networks
View all reports →