Progress Flowmon ADS Cross-Site Scripting Vulnerability

Vulnerability

A cross-site scripting vulnerability has been identified in Progress Flowmon ADS versions prior to 12.5.5 and 13.0.3. This issue allows an administrator to unintentionally perform actions within their authenticated web session by clicking on a malicious link sent by an attacker.

Impact

Exploitation of this vulnerability could lead to cross-site scripting, allowing for the injection of malicious scripts that could be executed in the context of the user's session.

Remediation

Users are advised to upgrade to Progress Flowmon ADS 12.5.5 or 13.0.3. The upgrade should be performed using the full installer, and there will be a system outage during the upgrade process. Upgrade packages are available through the Progress Community or the Progress Community Portal.

Added: Mar 12, 2026, 1:19 PM
Updated: Mar 12, 2026, 1:19 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
5.4
exploitability
6.2
remediation
0.0
relevance
3.8
threat
0.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.