PT-2025-41379 · Progress · Flowmon

Published

2025-10-09

·

Updated

2025-10-09

·

CVE-2025-10240

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Progress Flowmon versions prior to 12.5.5
Description A flaw exists in the Progress Flowmon web application that allows an attacker to manipulate authenticated users through malicious links. Clicking a crafted link can trigger unintended actions within a user's session, potentially leading to unauthorized operations or data exposure.
Recommendations Update to version 12.5.5 or later.

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2025-10240

Affected Products

Flowmon