Description
Multiple cross-site scripting (XSS) vulnerabilities in the web-based console management interface in Palo Alto Networks Traps (formerly Cyvera Endpoint Protection) 3.1.2.1546 allow remote attackers to inject arbitrary web script or HTML via the (1) Arguments, (2) FileName, or (3) URL parameter in a SOAP request.
CVSS Metrics
- Vector
- AV:N/AC:M/Au:N/C:N/I:P/A:N
- Access Vector
- network
- Access Cmplx
- medium
- Auth
- none
- Confidentiality
- none
- Integrity
- partial
- Availability
- none
- Weaknesses
- CWE-79
Metadata
- Primary Vendor
- PALO_ALTO_NETWORKS
- Published
- 4/14/2015
- Last Modified
- 4/12/2025
- Source
- NIST NVD
- Note: Verify all details with official vendor sources before applying patches.
Affected Products
palo_alto_networks : traps
AI-Powered Remediation
Generate remediation guidance or a C-suite brief for this vulnerability.