PT-2026-5099 · Unknown · Sync Breeze Enterprise Server+1

Rafael Pedrero

·

Publicado

2026-01-28

·

Atualizado

2026-02-10

·

CVE-2025-59891

CVSS v4.0

8.5

Alta

VetorAV:N/AC:L/AT:N/PR:L/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Sync Breeze Enterprise Server versions 10.4.18 Disk Pulse Enterprise versions 10.4.18
Description A cross-site request forgery (CSRF) issue exists in the software. An authenticated user can potentially cause another user to perform unintended actions within their logged-in session. This is due to missing CSRF token implementation. Exploitation involves a POST request to the /setup login?sid= endpoint, impacting the username, password, and cpassword parameters.
Recommendations Apply updates to versions beyond 10.4.18.

Correção

CSRF

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2025-59891

Produtos afetados

Diskpulse Enterprise
Sync Breeze Enterprise Server