Metrics
Affected Vendors & Products
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-1501 | A reflected cross-site scripting (XSS) vulnerability in Palo Alto Networks Expedition enables attackers to execute malicious JavaScript code in the context of an authenticated Expedition user’s browser if that authenticated user clicks a malicious link that allows phishing attacks and could lead to Expedition browser-session theft. |
Solution
No solution given by the vendor.
Workaround
Ensure that all network access to Expedition is restricted to only authorized users, hosts, and networks. If you are not actively using Expedition, make sure that your Expedition software is shut down.
| Link | Providers |
|---|---|
| https://security.paloaltonetworks.com/PAN-SA-2025-0001 |
|
Fri, 23 Jan 2026 22:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Paloaltonetworks
Paloaltonetworks expedition |
|
| CPEs | cpe:2.3:a:paloaltonetworks:expedition:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Paloaltonetworks
Paloaltonetworks expedition |
|
| Metrics |
cvssV3_1
|
Mon, 13 Jan 2025 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Sat, 11 Jan 2025 03:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A reflected cross-site scripting (XSS) vulnerability in Palo Alto Networks Expedition enables attackers to execute malicious JavaScript code in the context of an authenticated Expedition user’s browser if that authenticated user clicks a malicious link that allows phishing attacks and could lead to Expedition browser-session theft. | |
| Title | Expedition: Cross-Site Scripting (XSS) Vulnerability | |
| Weaknesses | CWE-79 | |
| References |
| |
| Metrics |
cvssV4_0
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: palo_alto
Published:
Updated: 2025-01-13T19:51:27.183Z
Reserved: 2024-12-20T23:23:02.943Z
Link: CVE-2025-0104
Updated: 2025-01-13T19:51:23.206Z
Status : Analyzed
Published: 2025-01-11T03:15:22.183
Modified: 2026-01-23T22:03:41.863
Link: CVE-2025-0104
No data.
OpenCVE Enrichment
No data.
EUVD