Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2025-59990


An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Juniper Networks Junos Space allows an attacker to inject script tags in the template creation pages that, when visited by another user, enable the attacker to execute commands with the target's permissions, including an administrator. This issue affects all versions of Junos Space before 24.1R4.


Published

2025-10-09T17:16:01.143

Last Modified

2026-01-23T20:00:25.657

Status

Analyzed

Source

[email protected]

Severity

CVSSv3.1: 6.1 (MEDIUM)

Weaknesses
  • Type: Secondary
    CWE-79

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application juniper junos_space < 24.1 Yes
Application juniper junos_space 24.1 Yes
Application juniper junos_space 24.1 Yes
Application juniper junos_space 24.1 Yes

References