CVE 8.5 HIGH

Cross-Site request forgery (CSRF) vulnerability in Sync Breeze Enterprise Server_CVE-2025-59892

8.5 / 10
HIGH
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

Description

Cross-Site request forgery (CSRF) vulnerability in Sync Breeze Enterprise Server v10.4.18 and Disk Pulse Enterprise v10.4.18. An authenticated user could cause another user to perform unwanted actions within the application they are logged into. This vulnerability is possible due to the lack of proper CSRF token implementation. Among other things, it is possible, using a POST request toย delete commands individually via '/delete_command?sid=', using the 'cid' parameter.

Basic Information

ID CVE-2025-59892
Source INCIBE
Published Jan 28, 2026 at 11:52

Affected Product

Vendor Flexense
Product Sync Breeze Enterprise Server
Version v10.4.18
Affected Versions Flexense Sync Breeze Enterprise Server v10.4.18
Flexense Disk Pulse Enterprise v10.4.18

CWE Classification

References

๐Ÿ’ญ Join the Security Discussion

๐Ÿ”’ Your email address will not be published. Required fields are marked *

โš ๏ธ Please be respectful and constructive in your comments. Security discussions should remain professional.