Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
cve-2025-0133 — Automated reflected XSS detection tool for CVE-2025-0133 targeting Palo Alto Networks GlobalProtect portal login pages with HTML and JavaScript context payloads. | Kitploit
Tools/GitHubGitHub/dodiorne/cve-2025-0133
Vulnerability ScannersExploitationWeb Application ExploitationWeb SecurityPenetration Testing
GitHubdodiorne/cve-2025-0133

cve-2025-0133

Automated reflected XSS detection tool for CVE-2025-0133 targeting Palo Alto Networks GlobalProtect portal login pages with HTML and JavaScript context payloads.

View Repository
421 year agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

CVE-2025-0133 Reflected XSS Detection Tool

Author: Derek Odiorne
Date: 2025-05-23
Severity: Medium
Tested Against: Palo Alto Networks GlobalProtect Portal (PAN-OS)


📌 Summary

This script performs safe, authorized testing for the vulnerability CVE-2025-0133, a reflected Cross-Site Scripting (XSS) issue in the GlobalProtect portal and gateway login pages of Palo Alto Networks' PAN-OS software.

The tool tests multiple common parameters with two context-specific payloads:

  • HTML context (<script>alert()</script>)
  • JavaScript string context (j\";-alert()...)

The results are colorized for clarity and saved in a timestamped log file.


🚨 Vulnerability Overview

  • CVE ID: CVE-2025-0133
  • Component: PAN-OS (GlobalProtect Portal / Gateway)
  • Vulnerability: Reflected XSS
  • Impact: JavaScript execution in the context of an authenticated user
  • Exploit Method: Maliciously crafted query parameter in a login URL

🧪 Usage

Prerequisites

  • Python 3.x
  • requests
  • colorama

Install dependencies (if needed):

pip install requests colorama
Download Tool