Flexense Sync Breeze Enterprise Server and Disk Pulse Enterprise Persistent Authenticated Cross-Site Scripting Vulnerability

Vulnerability

A persistent authenticated Cross-Site Scripting (XSS) vulnerability has been identified in Flexense Sync Breeze Enterprise Server and Disk Pulse Enterprise, both version 10.4.18. This vulnerability allows an attacker to send malicious content to an authenticated user, potentially stealing information from their session. The issue arises from inadequate validation of user input in several parameters via POST requests, specifically '/server_options?sid=', which affects the 'tasks_logs_dir', 'errors_logs_dir', 'error_notifications_address', 'status_notifications_address', and 'status_reports_address' parameters.

Impact

Exploitation of this vulnerability allows for persistent authenticated Cross-Site Scripting, where injected scripts are executed in the context of the user's session.

Added: Jan 28, 2026, 12:27 PM
Updated: Jan 28, 2026, 12:27 PM

Vulnerability Rating

Custom Algorithm
spread
2.6
impact
1.7
exploitability
4.2
remediation
0.0
relevance
2.4
threat
0.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.