Progress Flowmon ADS Cross-Site Scripting Vulnerability
Vulnerability
A cross-site scripting vulnerability has been identified in Progress Flowmon ADS versions prior to 12.5.5 and 13.0.3. This issue allows an administrator to unintentionally perform actions within their authenticated web session by clicking on a malicious link sent by an attacker.
Impact
Exploitation of this vulnerability could lead to cross-site scripting, allowing for the injection of malicious scripts that could be executed in the context of the user's session.
Remediation
Users are advised to upgrade to Progress Flowmon ADS 12.5.5 or 13.0.3. The upgrade should be performed using the full installer, and there will be a system outage during the upgrade process. Upgrade packages are available through the Progress Community or the Progress Community Portal.
Vulnerability Rating
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
