CVE-2023-0010
A reflected cross-site scripting vulnerability exists in the Captive Portal feature of Palo Alto Networks PAN-OS software. This issue applies to firewalls configured to use Captive Portal authentication, and on PAN-OS 10.0 and later only when default token generation for Captive Portal authentication is disabled.
Palo Alto Networks Security Advisory