CVE-2025-0104

A reflected cross-site scripting (XSS) vulnerability in Palo Alto Networks Expedition enables attackers to execute malicious JavaScript code in the context of an authenticated Expedition user’s browser if that authenticated user clicks a malicious link that allows phishing attacks and could lead to Expedition browser-session theft.
References
Configurations

Configuration 1 (hide)

cpe:2.3:a:paloaltonetworks:expedition:*:*:*:*:*:*:*:*

History

23 Jan 2026, 22:03

Type Values Removed Values Added
CPE cpe:2.3:a:paloaltonetworks:expedition:*:*:*:*:*:*:*:*
References () https://security.paloaltonetworks.com/PAN-SA-2025-0001 - () https://security.paloaltonetworks.com/PAN-SA-2025-0001 - Vendor Advisory
Summary
  • (es) Una vulnerabilidad de cross-site scripting (XSS) reflejado en Palo Alto Networks Expedition permite a los atacantes ejecutar código JavaScript malicioso en el contexto del navegador de un usuario autenticado de Expedition si ese usuario autenticado hace clic en un enlace malicioso que permite ataques de phishing y podría conducir al robo de la sesión del navegador de Expedition.
First Time Paloaltonetworks
Paloaltonetworks expedition
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 6.1

11 Jan 2025, 03:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-01-11 03:15

Updated : 2026-01-23 22:03


NVD link : CVE-2025-0104

Mitre link : CVE-2025-0104

CVE.ORG link : CVE-2025-0104


JSON object : View

Products Affected

paloaltonetworks

  • expedition
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')