### [CVE-2019-1566](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-1566) ![](https://img.shields.io/static/v1?label=Product&message=Palo%20Alto%20Networks%20PAN-OS&color=blue) ![](https://img.shields.io/static/v1?label=Version&message=n%2Fa&color=blue) ![](https://img.shields.io/static/v1?label=Vulnerability&message=Cross-Site%20Scripting%20(XSS)&color=brighgreen) ### Description The PAN-OS management web interface in PAN-OS 7.1.21 and earlier, PAN-OS 8.0.14 and earlier, and PAN-OS 8.1.5 and earlier, may allow an unauthenticated attacker to inject arbitrary JavaScript or HTML. ### POC #### Reference - https://www.purplemet.com/blog/palo-alto-firewall-multiple-xss-vulnerabilities #### Github No PoCs found on GitHub currently.