CVE-2025-59891HIGH 8.0EPSS p2.7%

CVE-2025-59891CVE-2025-59891

Description

Cross-Site request forgery (CSRF) vulnerability in Sync Breeze Enterprise Server v10.4.18 and Disk Pulse Enterprise v10.4.18. An authenticated user could cause another user to perform unwanted actions within the application they are logged into. This vulnerability is possible due to the lack of proper CSRF token implementation. Among other things, it is possible, using a POST request to change a user's password or create users via '/setup_login?sid=', affecting the 'username', 'password', and 'cpassword' parameters.

Scoring

CVSS 3.18.0 (HIGH)
VectorCVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
EPSS0.13% probability of exploitation · percentile 2.7% · 2026-06-17T12:03:21Z
Published2026-01-28
Last modified2026-02-10

Underlying weaknesses· 1

CWE-352

References

  1. https://www.incibe.es/en/incibe-cert/notices/aviso/multiple-vulnerabilities-flexense-products

1

TypeTargetConfidenceTier
WeaknessCross-Site Request Forgery (CSRF)cwe-3520%live

Related by meaning· 6

Nearest entities by semantic similarity across the cs-graph corpus.

CVE
CVE-2025-59893
CVE
CVE-2025-59892
CVE
CVE-2025-59894
CVE
CVE-2025-58469
CVE
CVE-2025-55057
CVE
CVE-2025-46385
Sourced from NVD + FIRST.org EPSS. Curated for EU compliance use cases by Adam Lundqvist, Founder at SQUR.