CVE 8.4 HIGH

Junos Space Security Director: Persistent Cross-Site Scripting (XSS) vulnerability_CVE-2025-59974

8.4 / 10
HIGH
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:H/I:H/A:H

Description

An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Junos Space Security Director allows an attacker to inject malicious scripts into the application, which are then stored and executed in the context of other users' browsers when they access affected pages.This issue affects Juniper Security Director: 

* All versions before 24.1R4.

Basic Information

ID CVE-2025-59974
Source juniper
Published Oct 9, 2025 at 15:57

Affected Product

Vendor Juniper Networks
Product Junos Space Security Director
Affected Versions Juniper Networks Junos Space Security Director 0

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.