PT-2026-24949 · Progress · Flowmon Ads+1
CVE-2026-2514
·
Publicado
2026-03-12
·
Atualizado
2026-03-13
CVSS v4.0
8.6
Alta
| Vetor | AV:A/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:L/SI:L/SA:N |
Name of the Vulnerable Software and Affected Versions
Progress Flowmon ADS versions prior to 12.5.5
Progress Flowmon ADS versions prior to 13.0.3
Description
A security issue exists in Progress Flowmon ADS that allows an attacker with access to Flowmon monitoring ports to create malicious network data. When this data is processed by Flowmon ADS and viewed by an authenticated user, unintended actions can be executed within the user's browser context. The issue involves crafting malicious data that impacts the web application when viewed by a user.
Recommendations
Versions prior to 12.5.5 should be updated to version 12.5.5 or later.
Versions prior to 13.0.3 should be updated to version 13.0.3 or later.
Correção
XSS
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Flowmon Ads
Flowmon Anomaly Detection System