CVE-2024-9467: Palo Alto Networks Expedition
Medium severity, CVSS 6.1. EPSS: 0.7% chance of exploitation in the next 30 days.
A reflected XSS vulnerability in Palo Alto Networks Expedition enables execution of malicious JavaScript in the context of an authenticated Expedition user's browser if that user clicks on a malicious link, allowing phishing attacks that could lead to Expedition browser session theft.
Affected products
- Palo Alto Networks Expedition: from 1.2.0, before 1.2.96 (fixed in 1.2.96)
Published 2024-10-09. Last modified 2026-06-17.