CVE-2025-59901

Disk Pulse Enterprise v10.4.18 has an authenticated reflected XSS vulnerability in the '/monitor_directory?sid=' endpoint, caused by insufficient validation of the 'monitor_directory' parameter sent by POST. An attacker could exploit this weakness to send malicious content to an authenticated user and steal information from their session.
CVSS

No CVSS.

Configurations

No configuration.

History

No history.

Information

Published : 2026-01-28 12:15

Updated : 2026-01-29 16:31


NVD link : CVE-2025-59901

Mitre link : CVE-2025-59901

CVE.ORG link : CVE-2025-59901


JSON object : View

Products Affected

No product.

CWE
CWE-352

Cross-Site Request Forgery (CSRF)