Progress Flowmon Cross-Site Scripting Vulnerability Allowing Session Hijacking

Vulnerability

A cross-site scripting vulnerability has been identified in the Progress Flowmon web application, affecting versions prior to 12.5.5. This vulnerability allows an attacker to manipulate a link that, when clicked by a user, triggers unintended actions within the user's authenticated session.

Impact

Exploitation of this vulnerability could lead to session hijacking, allowing an attacker to perform actions on behalf of the victim user.

Remediation

Users are advised to upgrade to Progress Flowmon version 12.5.5 or later. Upgrade packages are available through the Progress Community Portal. Note that upgrading to a patched release will require a system outage.

Added: Oct 9, 2025, 1:20 PM
Updated: Oct 9, 2025, 4:03 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
0.6
exploitability
6.4
remediation
4.7
relevance
0.6
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.