6.9
/ 10
MEDIUM
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/SC:N/VI:L/SI:N/VA:N/SA:N/E:U/S:N/AU:N/U:Amber/R:U/V:D/RE:M
Description
CVE-2025-0133 Palo Alto PAN-OS reflected XSS in the GlobalProtect gateway and portal getconfig.esp handler. The user query parameter is reflected unencoded into the Captive Portal page; an attacker who lures an authenticated GlobalProtect user to a...
Basic Information
ID
BDD2BFB9-2490-558F-B2CE-A14B786899D3
Published
May 6, 2026 at 23:51
Modified
May 6, 2026 at 23:56