Web Application Vulnerability in Progress Flowmon
CVE-2025-10240

8.8HIGH

Key Information:

Status
Vendor
CVE Published:
9 October 2025

What is CVE-2025-10240?

A vulnerability exists in the Progress Flowmon web application prior to version 12.5.5, allowing attackers to exploit user sessions. Users clicking a manipulated link could unintentionally trigger unauthorized actions within their authenticated sessions, posing a significant security risk. It is crucial for users to update to the latest version and remain aware of potential phishing attempts that could exploit this vulnerability.

Affected Version(s)

Flowmon Versions prior to 12.5.5

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

This vulnerability was discovered by Novee.
.
CVE-2025-10240 : Web Application Vulnerability in Progress Flowmon