CVE-2024-9467
CVSS 3.1 Score 6.1 of 10 (medium)
Details
Summary
CVE-2024-9467 is a reflected XSS (Cross-Site Scripting) vulnerability affecting Palo Alto Networks Expedition. This issue allows an attacker to inject malicious JavaScript into a webpage viewed by an authenticated Expedition user. If the user clicks on a specially crafted link, the malicious script is executed in their browser in the context of the Expedition session. This vulnerability poses a significant phishing risk, as an attacker could steal the user's Expedition session information, potentially leading to unauthorized access to sensitive data. Users are advised to exercise caution when clicking on links and to ensure they are using the latest version of the Expedition software, which contains a patch for this vulnerability.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- Paloaltonetworks Expedition
Affected Vendors
- Palo Alto Networks