Expedition: Reflected Cross-Site Scripting Vulnerability Leads to Expedition Session Disclosure
CVE-2024-9467
6.1MEDIUM
Key Information:
- Vendor
Palo Alto Networks
- Status
- Vendor
- CVE Published:
- 9 October 2024
Badges
👾 Exploit Exists
What is CVE-2024-9467?
A reflected XSS vulnerability in Palo Alto Networks Expedition enables execution of malicious JavaScript in the context of an authenticated Expedition user's browser if that user clicks on a malicious link, allowing phishing attacks that could lead to Expedition browser session theft.
Affected Version(s)
Expedition 1.2.0 < 1.2.96