CVE-2024-9467

CVSS 3.1 Score 6.1 of 10 (medium)

Details

Published Oct 9, 2024
Updated: Oct 15, 2024
CWE ID 79

Summary

CVE-2024-9467 is a reflected XSS (Cross-Site Scripting) vulnerability affecting Palo Alto Networks Expedition. This issue allows an attacker to inject malicious JavaScript into a webpage viewed by an authenticated Expedition user. If the user clicks on a specially crafted link, the malicious script is executed in their browser in the context of the Expedition session. This vulnerability poses a significant phishing risk, as an attacker could steal the user's Expedition session information, potentially leading to unauthorized access to sensitive data. Users are advised to exercise caution when clicking on links and to ensure they are using the latest version of the Expedition software, which contains a patch for this vulnerability.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Affected Products

  • Paloaltonetworks Expedition

Affected Vendors

  • Palo Alto Networks