Progress Flowmon Cross-Site Scripting Vulnerability Allowing Session Hijacking
Vulnerability
A cross-site scripting vulnerability has been identified in the Progress Flowmon web application, affecting versions prior to 12.5.5. This vulnerability allows an attacker to manipulate a link that, when clicked by a user, triggers unintended actions within the user's authenticated session.
Impact
Exploitation of this vulnerability could lead to session hijacking, allowing an attacker to perform actions on behalf of the victim user.
Remediation
Users are advised to upgrade to Progress Flowmon version 12.5.5 or later. Upgrade packages are available through the Progress Community Portal. Note that upgrading to a patched release will require a system outage.
Vulnerability Rating
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
