An SQL injection vulnerability in Palo Alto Networks Expedition enables an authenticated attacker to reveal Expedition database contents, such as password hashes, usernames, device configurations, and device API keys. This vulnerability also enables attackers to create and read arbitrary files on the Expedition system.
CVSS
No CVSS.
References
Link | Resource |
---|---|
https://security.paloaltonetworks.com/PAN-SA-2025-0001 |
Configurations
No configuration.
History
11 Jan 2025, 03:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2025-01-11 03:15
Updated : 2025-01-11 03:15
NVD link : CVE-2025-0103
Mitre link : CVE-2025-0103
CVE.ORG link : CVE-2025-0103
JSON object : View
Products Affected
No product.
CWE
CWE-89
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')