← voltar
CVE-2025-59985

Junos Space: Purging Policy field is vulnerable to reflected cross-site script injection

CVSS 5.1 MEDIUMEPSS 0.2%CWE-79
An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Juniper Networks Junos Space allows an attacker to inject script tags in a field on the Purging Policy page that, when visited by another user, enables the attacker to execute commands with the target's permissions, including an administrator.This issue affects all versions of Junos Space before 24.1R4.
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N

Quer saber se a sua infraestrutura está exposta a isto?

Falar com a TrueHacking →