Back to search
CVE-2025-59901
Published: Jan 28, 2026
Modified: Jan 28, 2026
PUBLISHED
Description
Disk Pulse Enterprise v10.4.18 has an authenticated reflected XSS vulnerability in the '/monitor_directory?sid=' endpoint, caused by insufficient validation of the 'monitor_directory' parameter sent by POST. An attacker could exploit this weakness to send malicious content to an authenticated user and steal information from their session.
| Vendor | Product | Versions |
|---|---|---|
Flexense | Sync Breeze Enterprise Server | affected v10.4.18 |
Flexense | Disk Pulse Enterprise | affected v10.4.18 |
Weaknesses (CWE)
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now