CWE-CWE-79

PAN-OS GlobalProtect XSS (CVE-2025-0133)

Severity:
Medium
Summary

Palo Alto Networks next-generation firewall (NGFW) is one of the leading enterprise firewalls used by companies around the world to protect against various cyber-attacks. It runs on its own operating system PAN-OS.

A reflected cross-site scripting (XSS) vulnerability exists in GlobalProtect gateway and portal features of PAN-OS. A remote attacker able to convince a user with an active authenticated session on the firewall web interface to click on a crafted link could potentially execute arbitrary JavaScript code in the user's browser and hijack the user's session.

Impact

A remote attacker can potentially execute arbitrary JavaScript code in the user's browser and hijack the user's session in GlobalProtect.

Remediation

Upgrade to the latest version of Palo Alto PAN-OS.

Required Skills for Successful Exploitation
Actions To Take
Classifications
Vulnerability Index

You can search and find all vulnerabilities

Featured resources

Blog

Strengthening enterprise application security: Invicti acquires Kondukto

Blog

Modern AppSec KPIs: Moving from scan counts to real risk reduction

Blog

Friends don’t let friends shift left: Shift smarter with DAST-first AppSec

Blog

Vibe talking: Dan Murphy on the promises, pitfalls, and insecurities of vibe coding

Blog

Strengthening enterprise application security: Invicti acquires Kondukto

Blog

Modern AppSec KPIs: Moving from scan counts to real risk reduction

Blog

Friends don’t let friends shift left: Shift smarter with DAST-first AppSec

Blog

Vibe talking: Dan Murphy on the promises, pitfalls, and insecurities of vibe coding