← Back

CVE-2022-0020

nvd nist
Published: Feb 10, 2022Modified: Jun 17, 2026

JSON object

Loading...
5.4
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Exploitability: 2.3 / Impact: 2.7
Source: NVD

Description

A stored cross-site scripting (XSS) vulnerability in Palo Alto Network Cortex XSOAR web interface enables an authenticated network-based attacker to store a persistent javascript payload that will perform arbitrary actions in the Cortex XSOAR web interface on behalf of authenticated administrators who encounter the payload during normal operations. This issue impacts: All builds of Cortex XSOAR 6.1.0; Cortex XSOAR 6.2.0 builds earlier than build 1958888.

Affected (13)

Cortex Xsoar
Configuration A
13 vulnerable
Vulnerable SoftwareAffected Versions
Paloaltonetworks
Version 6.1.0
Version 6.1.0 1016923
Version 6.1.0 1031903
Version 6.1.0 1077664
Version 6.1.0 1209934
Version 6.1.0 1271079
Version 6.1.0 848144
Version 6.2.0
Version 6.2.0 1271082
Version 6.2.0 1321594
Version 6.2.0 1473927
Version 6.2.0 1578666
Version 6.2.0 1822745

References (4)

Timeline

No history available yet.