Cross-Site request forgery (CSRF) vulnerability in Sync Breeze Enterprise Server v10.4.18 and Disk Pulse Enterprise v10.4.18. An authenticated user could cause another user to perform unwanted actions within the application they are logged into. This vulnerability is possible due to the lack of proper CSRF token implementation. Among other things, it is possible, using a POST request to change a user's password or create users via '/setup_login?sid=', affecting the 'username', 'password', and 'cpassword' parameters.
History

Wed, 28 Jan 2026 12:00:00 +0000

Type Values Removed Values Added
Description Cross-Site request forgery (CSRF) vulnerability in Sync Breeze Enterprise Server v10.4.18 and Disk Pulse Enterprise v10.4.18. An authenticated user could cause another user to perform unwanted actions within the application they are logged into. This vulnerability is possible due to the lack of proper CSRF token implementation. Among other things, it is possible, using a POST request to change a user's password or create users via '/setup_login?sid=', affecting the 'username', 'password', and 'cpassword' parameters.
Title Cross-Site request forgery (CSRF) vulnerability in Sync Breeze Enterprise Server
First Time appeared Flexense
Flexense disk Pulse Enterprise
Flexense sync Breeze Enterprise Server
Weaknesses CWE-352
CPEs cpe:2.3:a:flexense:disk_pulse_enterprise:v10.4.18:*:*:*:*:*:*:*
cpe:2.3:a:flexense:sync_breeze_enterprise_server:v10.4.18:*:*:*:*:*:*:*
Vendors & Products Flexense
Flexense disk Pulse Enterprise
Flexense sync Breeze Enterprise Server
References
Metrics cvssV4_0

{'score': 8.5, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: INCIBE

Published:

Updated: 2026-01-28T15:46:23.117Z

Reserved: 2025-09-23T10:22:34.912Z

Link: CVE-2025-59891

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-01-28T12:15:50.540

Modified: 2026-01-28T12:15:50.540

Link: CVE-2025-59891

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.