Record summary

CVE-2022-0020 has a selected CVSS score of 6.8 (medium); EIP currently links 1 catalogued exploit.

Description

A stored cross-site scripting (XSS) vulnerability in Palo Alto Network Cortex XSOAR web interface enables an authenticated network-based attacker to store a persistent javascript payload that will perform arbitrary actions in the Cortex XSOAR web interface on behalf of authenticated administrators who encounter the payload during normal operations. This issue impacts: All builds of Cortex XSOAR 6.1.0; Cortex XSOAR 6.2.0 builds earlier than build 1958888.

Description source: CVE List

Exploitation context

Available material

Catalogued exploits
1

Affected products and versions

1
ProductSourceVersion rangeStatus
CVE List6.5.0 allunaffected
6.1.0 allaffected
6.2.0 to < 1958888affected

Proofs of concept

1

Catalogued exploits

ExploitDBPalo Alto Cortex XSOAR 6.5.0 - Stored Cross-Site Scripting (XSS)ExploitDB exploitby omurugurNot analyzed1 file
ExploitDB

PoC details

References

3