NONE · 0

CVE-2025-59901

Disk Pulse Enterprise v10.4.18 has an authenticated reflected XSS vulnerability in the '/monitor_directory?sid=' endpoint, caused by insufficient validation of the 'monitor_directory' parameter sent b...

Vulnerability Description

Disk Pulse Enterprise v10.4.18 has an authenticated reflected XSS vulnerability in the '/monitor_directory?sid=' endpoint, caused by insufficient validation of the 'monitor_directory' parameter sent by POST. An attacker could exploit this weakness to send malicious content to an authenticated user and steal information from their session.

Related Weaknesses (CWE)

References

FAQ

What is CVE-2025-59901?

CVE-2025-59901 is a documented vulnerability. Disk Pulse Enterprise v10.4.18 has an authenticated reflected XSS vulnerability in the '/monitor_directory?sid=' endpoint, caused by insufficient validation of the 'monitor_directory' parameter sent b...

How severe is CVE-2025-59901?

CVSS scoring is not yet available for CVE-2025-59901. Check NVD for updates.

Is there a patch for CVE-2025-59901?

Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.