Persistent Authenticated XSS Vulnerability in Sync Breeze and Disk Pulse by Flexense
CVE-2025-59897
What is CVE-2025-59897?
The Sync Breeze Enterprise Server and Disk Pulse Enterprise software versions 10.4.18 are susceptible to a persistent authenticated Cross-Site Scripting (XSS) vulnerability. This issue arises from inadequate input validation in the '/edit_command?sid=' endpoint, specifically affecting the 'source_dir' and 'dest_dir' parameters. An attacker can exploit this flaw by sending specially crafted malicious content to authenticated users, allowing them to gain unauthorized access to user sessions and extract sensitive information.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Disk Pulse Enterprise v10.4.18
Sync Breeze Enterprise Server v10.4.18
References
CVSS V4
Timeline
Vulnerability published
Vulnerability Reserved
