PT-2026-5099 · Unknown · Sync Breeze Enterprise Server+1

Rafael Pedrero

·

Published

2026-01-28

·

Updated

2026-02-10

·

CVE-2025-59891

CVSS v4.0

8.5

High

VectorAV:N/AC:L/AT:N/PR:L/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Sync Breeze Enterprise Server versions 10.4.18 Disk Pulse Enterprise versions 10.4.18
Description A cross-site request forgery (CSRF) issue exists in the software. An authenticated user can potentially cause another user to perform unintended actions within their logged-in session. This is due to missing CSRF token implementation. Exploitation involves a POST request to the /setup login?sid= endpoint, impacting the username, password, and cpassword parameters.
Recommendations Apply updates to versions beyond 10.4.18.

Fix

CSRF

Weakness Enumeration

Related Identifiers

CVE-2025-59891

Affected Products

Diskpulse Enterprise
Sync Breeze Enterprise Server