Security Research

CVE-2025-0133 GlobalProtect Gateway Reflected XSS: credential theft at the VPN portal

#Vulnerability Analysis#Code Audit#Cyber Attack
CVE-2025-0133 GlobalProtect Gateway Reflected XSS: credential theft at the VPN portal

The Palo Alto GlobalProtect VPN gateway login page does not filter user input. An attacker injects JavaScript via a malicious URL to steal user credentials.

Unlock to view this content.