Executive brief
Progress Flowmon is a network monitoring and security analysis solution. A vulnerability exists where an administrator could be tricked into clicking a malicious link, allowing an attacker to perform unauthorized actions within the administrator's active web session. This could lead to unauthorized configuration changes or access to sensitive monitoring data.
Technical details
A cross-site scripting (XSS) vulnerability (CWE-79) exists in Progress Flowmon versions prior to 12.5.8 and 13.0.6. The flaw allows an unauthenticated remote attacker to craft a malicious link that, when clicked by an authenticated administrator, executes arbitrary commands or actions within the context of the victim's browser session. This is a reflected XSS issue requiring user interaction. Successful exploitation could allow an attacker to bypass security controls or modify system settings. Progress Software has released patches in versions 12.5.8 and 13.0.6 to address this issue.
Affected products
- Progress Software Flowmon 12.x versions prior to 12.5.8, 13.x versions prior to 13.0.6
Timeline
- 2026-04-02: disclosed
- 2026-04-02: advisory