CVE-2025-0103
Severity CVSS v4.0:
CRITICAL
Type:
CWE-89
SQL Injection
Publication date:
11/01/2025
Last modified:
23/01/2026
Description
An SQL injection vulnerability in Palo Alto Networks Expedition enables an authenticated attacker to reveal Expedition database contents, such as password hashes, usernames, device configurations, and device API keys. This vulnerability also enables attackers to create and read arbitrary files on the Expedition system.
Impact
Base Score 4.0
9.20
Severity 4.0
CRITICAL
Base Score 3.x
8.80
Severity 3.x
HIGH
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:paloaltonetworks:expedition:*:*:*:*:*:*:*:* | 1.2.101 (excluding) |
To consult the complete list of CPE names with products and versions, see this page



