CVE-2025-0104: Expedition: Cross-Site Scripting (XSS) Vulnerability
A reflected cross-site scripting (XSS) vulnerability in Palo Alto Networks Expedition enables attackers to execute malicious JavaScript code in the context of an authenticated Expedition user’s browser if that authenticated user clicks a malicious link that allows phishing attacks and could lead to Expedition browser-session theft.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-0104?
CVE-2025-0104 is classified as a reflected cross-site scripting (XSS) vulnerability, which poses a significant security risk to affected users.
How do I fix CVE-2025-0104?
To fix CVE-2025-0104, ensure that you are using the latest version of Palo Alto Networks Expedition and follow any recommended security updates.
Who is affected by CVE-2025-0104?
CVE-2025-0104 affects authenticated users of Palo Alto Networks Expedition when they are tricked into clicking malicious links.
What type of attack can exploit CVE-2025-0104?
CVE-2025-0104 can be exploited through phishing attacks that utilize malicious links to execute JavaScript code in the victim's browser.
What kind of issue does CVE-2025-0104 represent?
CVE-2025-0104 represents a reflected cross-site scripting (XSS) issue that can compromise user session and sensitive data.