Executive brief
Progress Flowmon ADS is a network traffic analysis and monitoring platform used by organizations to track and analyze network flows. A vulnerability allows attackers to trick administrators into clicking a malicious link, which then performs unintended actions in their authenticated web session—such as modifying configurations, creating accounts, or exfiltrating data. This could lead to unauthorized changes to network monitoring policies or security compromise.
Technical details
This is a Cross-Site Request Forgery (CSRF) vulnerability affecting Progress Flowmon ADS versions prior to 12.5.5 and 13.0.3. The vulnerability exists in the web interface and allows an attacker to craft a malicious link that, when clicked by an authenticated administrator, executes unintended actions within the user's authenticated session without proper request validation or CSRF token protection. No special privileges or network access is required beyond the ability to trick an administrator into clicking a link (social engineering). The vulnerability is fixed in Flowmon ADS 12.5.5 and 13.0.3 or later.
Affected products
- Progress Flowmon ADS prior to 12.5.5 and 13.0.3
Timeline
- 2026-03-12: disclosed