This is a heavily interactive web application, and JavaScript is required. Simple HTML interfaces are possible, but that is not what this is.
Post
Matthew Flanagan
mattimustang.com
did:plc:dpjekobhpc7rrcophvdie3hy
Any threat actor who gets one of those files gets your LDAP service account and walks straight off the firewall into your AD.
This is not theoretical.
Palo's own Unit 42 [3] documented attackers copying running-config.xml to a web-accessible path and retrieving it after exploiting CVE-2024-3400.
2026-08-18T11:39:04.242Z