Cross-Site Request Forgery Vulnerability in Flexense Products
CVE-2025-59891

8.5HIGH

What is CVE-2025-59891?

A Cross-Site Request Forgery (CSRF) vulnerability exists in both Sync Breeze Enterprise Server v10.4.18 and Disk Pulse Enterprise v10.4.18. This security flaw allows an authenticated user to trick another user into executing unintended actions within the application session by leveraging improper handling of CSRF tokens. An attacker can exploit this vulnerability through a crafted POST request, potentially leading to unauthorized password changes or user account creations, thereby compromising user credentials and application integrity.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

Affected Version(s)

Disk Pulse Enterprise v10.4.18

Sync Breeze Enterprise Server v10.4.18

References

CVSS V4

Score:
8.5
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Rafael Pedrero
.