CVE-2025-59898
Our Analysis: General Purpose
Our model has classified this vulnerability as relevant to General Purpose Systems, helping your team prioritize efforts effectively.
Published Date
January 28, 2026
Last Modified
January 29, 2026
CVSS Vector
Not Available
Description
Sync Breeze Enterprise Server v10.4.18 and Disk Pulse Enterprise v10.4.18 contain a persistent authenticated Cross-Site Scripting (XSS) vulnerability. An attacker could send malicious content to an authenticated user and steal information from their session due to insufficient validation of user input inĀ '/add_exclude_dir?sid=', affecting the 'exclude_dir' parameter.