PT-2025-41419 · Juniper Networks · Junos Space

Published

2025-10-09

·

Updated

2025-10-09

·

CVE-2025-59983

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Juniper Networks Junos Space versions prior to 24.1R4
Description An issue exists in Juniper Networks Junos Space that allows an attacker to inject script tags into the Template Definition page. When another user visits this page, the injected script can execute commands with the target user's permissions, potentially including administrator privileges. This occurs due to improper neutralization of input during web page generation, leading to a Cross-site Scripting condition.
Recommendations Update to Junos Space version 24.1R4 or later.

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2025-59983

Affected Products

Junos Space