CVE-2024-0011
A reflected cross-site scripting (XSS) vulnerability in the Captive Portal feature of Palo Alto Networks PAN-OS software enables execution of malicious JavaScript (in the context of an authenticated Captive Portal user’s browser) if a user clicks on a malicious link, allowing phishing attacks that could lead to credential theft.
More information : https://security.paloaltonetworks.com/CVE-2024-0011
Attack vector : NETWORK
Attack complexity : LOW
Privileges required : NONE
User interaction : REQUIRED
Confidentiality impact : LOW
Integrity impact : LOW
Base score : 6.1
Base severity : MEDIUM
Exploitability score : 2.8
Impact score : 2.7