目标达成 感谢每一位支持者 — 我们达成了 100% 目标!

目标: 1000 元 · 已筹: 1336

100%

CVE-2025-0133 PoC — Palo Alto Networks PAN-OS 安全漏洞

来源
关联漏洞
标题:Palo Alto Networks PAN-OS 安全漏洞 (CVE-2025-0133)
Description:Palo Alto Networks PAN-OS是美国Palo Alto Networks公司的一套为其防火墙设备开发的操作系统。 Palo Alto Networks PAN-OS存在安全漏洞,该漏洞源于反射型跨站脚本可能导致钓鱼攻击。
Description
CVE-2025-0133 Exploit
介绍
# CVE-2025-0133
CVE-2025-0133 Exploit
CVE-2025-0133 is a reflected cross-site scripting (XSS) vulnerability in the GlobalProtect™ gateway and portal features of Palo Alto Networks PAN-OS® software. An authenticated user with access to the Captive Portal can be tricked into clicking a specially crafted link, leading to the execution of arbitrary JavaScript in the context of their browser. This could result in session hijacking, credential theft, or other client-side attacks.

Severity: Medium (CVSS v3.1 Base Score: 6.1; Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N)
Affected Versions:

PAN-OS 11.2 < 11.2.7
PAN-OS 11.1 < 11.1.11
PAN-OS 10.2 < 10.2.17


Published: May 14, 2025
Vendor Advisory: Palo Alto Networks Security Advisory
NVD Entry: CVE-2025-0133

Impact:

Execution of malicious JavaScript in the victim's browser.
Potential for phishing, data exfiltration, or further exploitation if combined with other vulnerabilities.
Limited impact on confidentiality for Clientless VPN users due to inherent risks (see PAN-SA-2025-0005).
文件快照

登录后查看神龙缓存的 POC 文件快照

登录查看
备注
    1. 建议优先通过来源进行访问。
    2. 本地 POC 快照面向订阅用户开放;当原始来源失效或无法访问时,本地镜像作为订阅权益的一部分提供。
    3. 持续抓取、验证、维护这份 POC 档案需要不少投入,因此本地快照已纳入付费订阅。您的订阅是让这份资料能继续走下去的关键,由衷感谢。 查看订阅方案 →