Vulnerability Description
An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Junos Space Security Director allows an attacker to inject malicious scripts into the application, which are then stored and executed in the context of other users' browsers when they access affected pages.This issue affects Juniper Security Director: * All versions before 24.1R4.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Juniper | Space Security Director | < 24.1 |
Related Weaknesses (CWE)
References
- https://supportportal.juniper.net/JSA103139Vendor Advisory
FAQ
What is CVE-2025-59974?
CVE-2025-59974 is a vulnerability with a CVSS score of 8.4 (HIGH). An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Junos Space Security Director allows an attacker to inject malicious scripts into the applicati...
How severe is CVE-2025-59974?
CVE-2025-59974 has been rated HIGH with a CVSS base score of 8.4/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2025-59974?
Check the references section above for vendor advisories and patch information. Affected products include: Juniper Space Security Director.