Version: PANOS 7.0.5
Summary: XSS issue in HTML used for the user login portal. An attacker can run arbitrary javascript by manipulating the username field. See attached screenshot
Steps to Reproduce:
1. Setup plain vanilla, standard HTTP captive portal, using the web form option
2. A user will be presented with the default captive portal.
3. As a username, enter something like (including all quotes):
";alert ('i can steal your cookies');var test="
4. Alert is shown (see screenshot)
----------------------
David Vassallo
Research and Development Director
6PM Business Center, Triq it-Torri, Swatar, B'Kara BKR 4012
Tel: +356 2258 4500 | Fax: +356 2148 9653