CVE-2025-10240: Possibility of unintended actions when a user clicks a malicious link in the Progress Flowmon web application
A vulnerability exists in the Progress Flowmon web application prior to version 12.5.5, whereby a user who clicks a malicious link provided by an attacker may inadvertently trigger unintended actions within their authenticated session.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-10240?
The severity of CVE-2025-10240 is classified as high due to its potential to enable unauthorized actions within an authenticated session.
How do I fix CVE-2025-10240?
To remediate CVE-2025-10240, upgrade the Progress Flowmon application to version 12.5.5 or later.
Which versions of Progress Flowmon are affected by CVE-2025-10240?
Versions of Progress Flowmon prior to 12.5.5 are affected by CVE-2025-10240.
What type of attack does CVE-2025-10240 exploit?
CVE-2025-10240 exploits a vulnerability that enables attackers to leverage malicious links to perform unintended actions in a user's authenticated session.
Is CVE-2025-10240 a remote attack vector?
Yes, CVE-2025-10240 can be exploited remotely by an attacker through social engineering techniques.