PT-2026-24949 · Progress · Flowmon Ads+1

CVE-2026-2514

·

Publicado

2026-03-12

·

Atualizado

2026-03-13

CVSS v4.0

8.6

Alta

VetorAV:A/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:L/SI:L/SA:N
Name of the Vulnerable Software and Affected Versions Progress Flowmon ADS versions prior to 12.5.5 Progress Flowmon ADS versions prior to 13.0.3
Description A security issue exists in Progress Flowmon ADS that allows an attacker with access to Flowmon monitoring ports to create malicious network data. When this data is processed by Flowmon ADS and viewed by an authenticated user, unintended actions can be executed within the user's browser context. The issue involves crafting malicious data that impacts the web application when viewed by a user.
Recommendations Versions prior to 12.5.5 should be updated to version 12.5.5 or later. Versions prior to 13.0.3 should be updated to version 13.0.3 or later.

Correção

XSS

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2026-2514

Produtos afetados

Flowmon Ads
Flowmon Anomaly Detection System