cbcvebase.
CVE-2025-59978
published 2025-10-09

CVE-2025-59978: An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Juniper Networks Junos Space allows an attacker to…

critical9.4CVSS 4.0
AVNACLATNPRLUIPVCHVIHVAHSCHSIHSAHEXCRXIRXARXMAVXMACXMATXMPRXMUIXMVCXMVIXMVAXMSCXMSIXMSAXSXAUXRUVXREMUX
An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Juniper Networks Junos Space allows an attacker to store script tags directly in web pages that, when viewed by another user, enable the attacker to execute commands with the target's administrative permissions. This issue affects all versions of Junos Space before 24.1R4.

Affected

5 ranges
VendorProductVersion rangeFixed in
juniperjunos_os
juniperjunos_space< 24.124.1
juniperjunos_space
juniperjunos_space
juniper_networksjunos_space< 24.1R424.1R4
CVE-2025-59978 — Cross-site Scripting | cvebase