CVE-2025-10240

8.8

Progress Software · Flowmon

A cross-site scripting (XSS) vulnerability in Progress Flowmon allows an attacker to execute unintended actions within an authenticated user session via a malicious link.

Executive summary

Progress Flowmon versions prior to 12.5.5 are susceptible to a cross-site scripting vulnerability that could lead to unauthorized actions within an active user session.

Vulnerability

This is a cross-site scripting (XSS) vulnerability, classified as CWE-79, which occurs when input is improperly neutralized. An unauthenticated attacker can leverage this flaw by tricking an authenticated user into clicking a malicious link, thereby triggering unauthorized actions in the user context.

Business impact

Successful exploitation of this vulnerability can result in significant security breaches, including session hijacking, unauthorized data modification, or the execution of administrative actions without user consent. Given the CVSS score of 8.8, this flaw poses a high risk to organizational integrity and confidentiality, particularly if the affected users possess elevated privileges within the Flowmon appliance.

Remediation

Immediate Action: Update the Progress Flowmon appliance to version 12.5.5 or later to resolve the underlying input neutralization flaw.

Proactive Monitoring: Review web access logs for suspicious URL parameters or unusual activity originating from external referrers that may indicate attempts to deliver malicious payloads.

Compensating Controls: Deploy a Web Application Firewall (WAF) with strict XSS filtering rules to intercept and block malformed requests containing script-based payloads.

Exploitation status

Public Exploit Available: Unknown.

Analyst recommendation

Organizations utilizing Progress Flowmon must prioritize the update to version 12.5.5 immediately to mitigate the risk of cross-site scripting attacks. Failure to apply this patch leaves the application and its users vulnerable to session-based compromise, which could be leveraged to gain further access into the management environment.

More Progress Software CVEs

Sources

Originally found and disclosed by This vulnerability was discovered by Novee., per the CVE Program record.