S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
medium·Product Based Web Vulnerabilities·Updated Jun 20, 2025

CVE-2025-0133 Scanner

CVE-2025-0133 Scanner - Cross-Site Scripting (XSS) vulnerability in PAN-OS

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, subdomain, ipv4
CostFree
2.8k
Times Used
continuous scan runs
5.8k
Continuously Checked
assets under CS
17
Vulnerabilities Found
confirmed findings
References
CVECVE-2025-0133
1.2
CVSSlow
Exploitable remotely over the internet · no authentication required.

A reflected cross-site scripting (XSS) vulnerability in the GlobalProtect™ gateway and portal features of Palo Alto Networks PAN-OS® software enables execution of malicious JavaScript in the context of an authenticated Captive Portal user's browser when they click on a specially crafted link. The primary risk is phishing attacks that can lead to credential theft—particularly if you enabled Clientless VPN. There is no availability impact to GlobalProtect features or GlobalProtect users. Attackers cannot use this vulnerability to tamper with or modify contents or configurations of the GlobalProtect portal or gateways. The integrity impact of this vulnerability is limited to enabling an attacker to create phishing and credential-stealing links that appear to be hosted on the GlobalProtect portal. For GlobalProtect users with Clientless VPN enabled, there is a limited impact on confidentiality due to inherent risks of Clientless VPN that facilitate credential theft. You can read more about this risk in the informational bulletin PAN-SA-2025-0005 https://security.paloaltonetworks.com/PAN-SA-2025-0005 https://security.paloaltonetworks.com/PAN-SA-2025-0005 . There is no impact to confidentiality for GlobalProtect users if you did not enable (or you disable) Clientless VPN.

Attack Vector
Network
Privileges Req.
None
User Interaction
A
Affected
Cloud NGFWby Palo Alto Networks
AFFECTED< 11.2.8SAFE ✓≥ 11.2.8
PAN-OSby Palo Alto Networks
AFFECTED< 11.2.7SAFE ✓≥ 11.2.7
Prisma Accessby Palo Alto Networks
All
Updated Sep 9, 2026View on NVD →
Detail

Palo Alto Networks' PAN-OS is used primarily by network administrators for securing network infrastructure and managing firewall configurations. It is integral in implementing security policies across enterprise-level networks, providing features such as VPN connectivity and traffic filtering. The GlobalProtect™ gateway and portal features allow for secure remote access to network resources. However, with heightened security needs, vulnerabilities within such systems present significant risks, particularly given the sensitive nature of the data handled by PAN-OS. PAN-OS operates in a variety of sectors including government, finance, healthcare, and education due to its comprehensive security offerings. As cyber threats evolve, maintaining the security integrity of such systems is paramount.

The reflected cross-site scripting (XSS) vulnerability in PAN-OS can lead to unauthorized script execution in users’ browsers. This vulnerability is particularly relevant when users are tricked into clicking on specially crafted links while authenticated in Captive Portal. Such vulnerabilities often serve as gateways for phishing attacks. When attackers execute malicious scripts, they can bypass security measures by exploiting the trust users place in authenticated sessions. The manipulation of session and credential information remains among the key impacts of such exploits. Primarily, phishing attacks facilitated by XSS can lead to data breaches involving sensitive user credentials.

Technical details of the XSS vulnerability in PAN-OS revolve around the manipulation of parameters sent to the GlobalProtect interface. The culprit lies in the handling of user input within URLs, where JavaScript can be injected and executed in the browser context. This happens because user inputs are not properly sanitized or validated, leading to reflected script injection. The lack of proper input handling allows attackers to render arbitrary HTML or client-side scripts. Key impersonated parameters in exploit attempts include those related to client identification and authentication, leading to trust misuse. Thus, an endpoint related to portal configurations becomes the entry point for exploitation.

Exploiting this XSS vulnerability may result in the unauthorized execution of scripts within trusted user sessions, leading to potential unauthorized access to sensitive information. Attackers can employ phishing techniques to steal credentials and other crucial user data. Users also face risks of manipulated content displays, session hijacking, and further secondary attacks facilitated by gathered data. The overarching consequence is the compromise of user trust and potential legal repercussions for data privacy violations. Moreover, prolonged exposure can lead to company-wide security downgrades and reputational damages.

REFERENCES

Solution Advice
  • Implement robust input validation and sanitization for all user inputs.
  • Employ Content Security Policy (CSP) headers to restrict script execution.
  • Regularly update PAN-OS to the latest version to safeguard against known vulnerabilities.
  • Utilize secure coding practices to prevent script injections.
  • Educate users on recognizing and avoiding phishing attempts and suspicious links.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

CVE-2025-0133 Scanner - Cross-Site Scripting (XSS) vulnerability in PAN-OS | S4E