Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2025-60000


An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Juniper Networks Junos Space allows an attacker to inject script tags in the Generate Report page that, when visited by another user, enables the attacker to execute commands with the target's permissions, including an administrator. This issue affects all versions of Junos Space before 24.1R4.


Published

2025-10-09T17:16:03.110

Last Modified

2026-01-23T20:00:32.320

Status

Analyzed

Source

[email protected]

Severity

CVSSv3.1: 6.1 (MEDIUM)

Weaknesses
  • Type: Secondary
    CWE-79

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application juniper junos_space < 24.1 Yes
Application juniper junos_space 24.1 Yes
Application juniper junos_space 24.1 Yes
Application juniper junos_space 24.1 Yes

References