CVE-2025-59901

Disk Pulse Enterprise v10.4.18 has an authenticated reflected XSS vulnerability in the '/monitor_directory?sid=' endpoint, caused by insufficient validation of the 'monitor_directory' parameter sent by POST. An attacker could exploit this weakness to send malicious content to an authenticated user and steal information from their session.
CVSS

No CVSS.

Configurations

No configuration.

History

15 Apr 2026, 00:35

Type Values Removed Values Added
Summary
  • (es) Disk Pulse Enterprise v10.4.18 tiene una vulnerabilidad XSS reflejada autenticada en el endpoint '/monitor_directory?sid=', causada por la validación insuficiente del parámetro 'monitor_directory' enviado por POST. Un atacante podría explotar esta debilidad para enviar contenido malicioso a un usuario autenticado y robar información de su sesión.

28 Jan 2026, 12:15

Type Values Removed Values Added
New CVE

Information

Published : 2026-01-28 12:15

Updated : 2026-06-17 09:46


NVD link : CVE-2025-59901

Mitre link : CVE-2025-59901

CVE.ORG link : CVE-2025-59901


JSON object : View

Products Affected

No product.

CWE
CWE-352

Cross-Site Request Forgery (CSRF)