CVE-2023-0010: Palo Alto Networks PAN-OS
Medium severity, CVSS 5.4. EPSS: 0.4% chance of exploitation in the next 30 days.
A reflected cross-site scripting (XSS) vulnerability in the Captive Portal feature of Palo Alto Networks PAN-OS software can allow a JavaScript payload to be executed in the context of an authenticated Captive Portal user’s browser when they click on a specifically crafted link.
Affected products
- Palo Alto Networks PAN-OS: from 8.1.0, up to and including 8.1.24; from 9.0.0, up to and including 9.0.17; from 9.1.0, up to and including 9.1.16; from 10.0.0, up to and including 10.0.11; from 10.1.0, up to and including 10.1.6; from 10.2.0, up to and including 10.2.2
Published 2023-06-14. Last modified 2026-06-17.