Cross-Site Request Forgery Vulnerability in Flexense Products
CVE-2025-59892

8.5HIGH

What is CVE-2025-59892?

A Cross-Site Request Forgery (CSRF) vulnerability in Sync Breeze Enterprise Server and Disk Pulse Enterprise allows authenticated users to exploit the lack of proper CSRF token implementation. This failure permits an attacker to trick another authorized user into executing unwanted actions within the application. Specifically, an attacker can initiate a POST request to delete commands individually by exploiting the '/delete_command?sid=' endpoint and manipulating the 'cid' parameter. Users of the affected versions should prioritize securing their applications against this type of attack.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

Affected Version(s)

Disk Pulse Enterprise v10.4.18

Sync Breeze Enterprise Server v10.4.18

References

CVSS V4

Score:
8.5
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Rafael Pedrero
.