CVE-2024-5906

A cross-site scripting (XSS) vulnerability in Palo Alto Networks Prisma Cloud Compute software enables a malicious administrator with add/edit permissions for identity providers to store a JavaScript payload using the web interface on Prisma Cloud Compute. This enables a malicious administrator to perform actions in the context of another user's browser when accessed by that other user.
CVSS

No CVSS.

Configurations

No configuration.

History

13 Jun 2024, 18:36

Type Values Removed Values Added
New CVE

Information

Published : 2024-06-12 17:15

Updated : 2024-06-13 18:36


NVD link : CVE-2024-5906

Mitre link : CVE-2024-5906

CVE.ORG link : CVE-2024-5906


JSON object : View

Products Affected

No product.

CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')