Palo Alto Networks PAN-OS before 8.1.4 GlobalProtect Portal Login page allows an unauthenticated attacker to inject arbitrary JavaScript or HTML, making it vulnerable to cross-site scripting.
View the template here CVE-2018-10141.yaml
References:
https://security.paloaltonetworks.com/CVE-2018-10141