← Volver a CVEs
CVE-2025-59892
HIGH8.0
Descripcion
Cross-Site request forgery (CSRF) vulnerability in Sync Breeze Enterprise Server v10.4.18 and Disk Pulse Enterprise v10.4.18. An authenticated user could cause another user to perform unwanted actions within the application they are logged into. This vulnerability is possible due to the lack of proper CSRF token implementation. Among other things, it is possible, using a POST request to delete commands individually via '/delete_command?sid=', using the 'cid' parameter.
Detalles CVE
Puntuacion CVSS v3.18.0
SeveridadHIGH
Vector CVSSCVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
Vector de ataqueNETWORK
ComplejidadLOW
Privilegios requeridosLOW
Interaccion usuarioREQUIRED
Publicado1/28/2026
Ultima modificacion2/10/2026
Fuentenvd
Avistamientos honeypot0
Productos afectados
flexense:diskpulseflexense:syncbreeze
Debilidades (CWE)
CWE-352
Referencias
https://www.incibe.es/en/incibe-cert/notices/aviso/multiple-vulnerabilities-flexense-products(cve-coordination@incibe.es)
Correlaciones IOC
Sin correlaciones registradas
This product uses data from the NVD API but is not endorsed or certified by the NVD.