vendor:
Palo Alto Traps Server (formerly Cyvera Endpoint Protection)
by:
Michael Hendrickx
7.5
CVSS
HIGH
Stored Cross Site Scripting
79
CWE
Product Name: Palo Alto Traps Server (formerly Cyvera Endpoint Protection)
Affected Version From: 3.1.2.1546
Affected Version To: 3.1.2.1546
Patch Exists: NO
Related CWE: CVE-2015-2223
CPE: cpe:2.3:a:paloaltonetworks:palo_alto_traps_server:3.1.2.1546:*:*:*:*:*:*:*
Platforms Tested:
2015
Palo Alto Traps Server Stored Cross Site Scripting Vulnerability
An attacker can send a SOAP request with JavaScript embedded inside it, which gets stored in the database. When an administrator monitors the Traps’ admin screen and opens details about the vulnerability, the JavaScript is executed on the admin browser.
Mitigation:
Contact the vendor for the patch details.