Disk Pulse Enterprise v10.4.18 has an authenticated reflected XSS vulnerability in the '/monitor_directory?sid=' endpoint, caused by insufficient validation of the 'monitor_directory' parameter sent by POST. An attacker could exploit this weakness to send malicious content to an authenticated user and steal information from their session.
Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Wed, 28 Jan 2026 12:15:00 +0000

Type Values Removed Values Added
Description Disk Pulse Enterprise v10.4.18 has an authenticated reflected XSS vulnerability in the '/monitor_directory?sid=' endpoint, caused by insufficient validation of the 'monitor_directory' parameter sent by POST. An attacker could exploit this weakness to send malicious content to an authenticated user and steal information from their session.
Title authenticated reflected XSS vulnerability in Sync Breeze Enterprise Server
First Time appeared Flexense
Flexense disk Pulse Enterprise
Flexense sync Breeze Enterprise Server
Weaknesses CWE-352
CPEs cpe:2.3:a:flexense:disk_pulse_enterprise:v10.4.18:*:*:*:*:*:*:*
cpe:2.3:a:flexense:sync_breeze_enterprise_server:v10.4.18:*:*:*:*:*:*:*
Vendors & Products Flexense
Flexense disk Pulse Enterprise
Flexense sync Breeze Enterprise Server
References
Metrics cvssV4_0

{'score': 8.5, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: INCIBE

Published:

Updated: 2026-01-28T15:16:54.606Z

Reserved: 2025-09-23T10:24:09.538Z

Link: CVE-2025-59901

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-01-28T12:15:51.897

Modified: 2026-01-28T12:15:51.897

Link: CVE-2025-59901

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses