CSRF Vulnerability in Sync Breeze Enterprise Server and Disk Pulse Enterprise
CVE-2025-59893

8.5HIGH

What is CVE-2025-59893?

A CSRF vulnerability exists in Sync Breeze Enterprise Server v10.4.18 and Disk Pulse Enterprise v10.4.18, allowing an authenticated user to trick another user into executing unauthorized actions in the application. The flaw arises from inadequate implementation of CSRF tokens, specifically enabling users to issue POST requests to rename commands via the '/rename_command?sid=' endpoint, which manipulates the 'command_name' parameter. This security lapse underscores the need for robust CSRF protection in web applications.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

Affected Version(s)

Disk Pulse Enterprise v10.4.18

Sync Breeze Enterprise Server v10.4.18

References

CVSS V4

Score:
8.5
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Rafael Pedrero
.