A vulnerability exists in Progress Flowmon versions prior to 12.5.8 and 13.0.6, whereby an administrator who clicks a malicious link provided by an attacker may inadvertently trigger unintended actions within their authenticated web session.
Metrics
Affected Vendors & Products
References
History
Thu, 02 Apr 2026 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 02 Apr 2026 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A vulnerability exists in Progress Flowmon versions prior to 12.5.8 and 13.0.6, whereby an administrator who clicks a malicious link provided by an attacker may inadvertently trigger unintended actions within their authenticated web session. | |
| Title | Possibility of unintended actions when an administrator clicks a malicious link in the Progress Flowmon web application | |
| Weaknesses | CWE-79 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: ProgressSoftware
Published:
Updated: 2026-04-02T13:52:24.790Z
Reserved: 2026-02-19T09:21:34.082Z
Link: CVE-2026-2737
Updated: 2026-04-02T13:51:34.715Z
Status : Received
Published: 2026-04-02T14:16:28.087
Modified: 2026-04-02T14:16:28.087
Link: CVE-2026-2737
No data.
OpenCVE Enrichment
No data.