CVE-2025-0104
EUVD-2025-150111.01.2025, 03:15
A reflected cross-site scripting (XSS) vulnerability in Palo Alto Networks Expedition enables attackers to execute malicious JavaScript code in the context of an authenticated Expedition user’s browser if that authenticated user clicks a malicious link that allows phishing attacks and could lead to Expedition browser-session theft.
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| paloaltonetworks | expedition | 𝑥 < 1.2.101 |
𝑥
= Vulnerable software versions