Flexense Disk Pulse Enterprise
cpe:2.3:a:flexense:disk_pulse:*:*:*:*:*:*:*, +1 more
- 10.4.18
A persistent authenticated Cross-Site Scripting (XSS) vulnerability has been identified in Flexense Sync Breeze Enterprise Server and Disk Pulse Enterprise, both version 10.4.18. This vulnerability allows an attacker to send malicious content to an authenticated user, potentially stealing information from their session. The issue arises from inadequate validation of user input in the '/add_exclude_dir?sid=' endpoint, specifically affecting the 'exclude_dir' parameter.
Exploitation of this vulnerability allows for persistent authenticated Cross-Site Scripting, where injected malicious scripts are executed in the context of the user's session.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.