Disk Pulse Enterprise v10.4.18 has an authenticated reflected XSS vulnerability in the '/monitor_directory?sid=' endpoint, caused by insufficient validation of the 'monitor_directory' parameter sent by POST. An attacker could exploit this weakness to send malicious content to an authenticated user and steal information from their session.
History

Wed, 28 Jan 2026 12:15:00 +0000

Type Values Removed Values Added
Description Disk Pulse Enterprise v10.4.18 has an authenticated reflected XSS vulnerability in the '/monitor_directory?sid=' endpoint, caused by insufficient validation of the 'monitor_directory' parameter sent by POST. An attacker could exploit this weakness to send malicious content to an authenticated user and steal information from their session.
Title authenticated reflected XSS vulnerability in Sync Breeze Enterprise Server
First Time appeared Flexense
Flexense disk Pulse Enterprise
Flexense sync Breeze Enterprise Server
Weaknesses CWE-352
CPEs cpe:2.3:a:flexense:disk_pulse_enterprise:v10.4.18:*:*:*:*:*:*:*
cpe:2.3:a:flexense:sync_breeze_enterprise_server:v10.4.18:*:*:*:*:*:*:*
Vendors & Products Flexense
Flexense disk Pulse Enterprise
Flexense sync Breeze Enterprise Server
References
Metrics cvssV4_0

{'score': 8.5, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: INCIBE

Published: 2026-01-28T12:01:30.669Z

Updated: 2026-01-28T12:01:30.669Z

Reserved: 2025-09-23T10:24:09.538Z

Link: CVE-2025-59901

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-01-28T12:15:51.897

Modified: 2026-01-28T12:15:51.897

Link: CVE-2025-59901

cve-icon Redhat

No data.