CSRF Vulnerability in Sync Breeze Enterprise Server and Disk Pulse Enterprise
CVE-2025-59893
What is CVE-2025-59893?
A CSRF vulnerability exists in Sync Breeze Enterprise Server v10.4.18 and Disk Pulse Enterprise v10.4.18, allowing an authenticated user to trick another user into executing unauthorized actions in the application. The flaw arises from inadequate implementation of CSRF tokens, specifically enabling users to issue POST requests to rename commands via the '/rename_command?sid=' endpoint, which manipulates the 'command_name' parameter. This security lapse underscores the need for robust CSRF protection in web applications.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Disk Pulse Enterprise v10.4.18
Sync Breeze Enterprise Server v10.4.18
References
CVSS V4
Timeline
Vulnerability published
Vulnerability Reserved
