Published using Google Docs
XSS issue in HTML used for the user login portal
Updated automatically every 5 minutes

 

Version: PANOS 7.0.5

Summary: XSS issue in HTML used for the user login portal. An attacker can run arbitrary javascript by manipulating the username field. See attached screenshot

Steps to Reproduce:

1. Setup plain vanilla, standard HTTP captive portal, using the web form option

2. A user will be presented with the default captive portal.

3. As a username, enter something like (including all quotes):

";alert ('i can steal your cookies');var test="

4. Alert is shown (see screenshot)

----------------------

David Vassallo

Research and Development Director

@dave_vassallo

www.6pmsolutions.com

6PM Business Center, Triq it-Torri, Swatar, B'Kara BKR 4012

Tel: +356 2258 4500 | Fax: +356 2148 9653