Cross-Site request forgery (CSRF) vulnerability in Sync Breeze Enterprise Server v10.4.18 and Disk Pulse Enterprise v10.4.18. An authenticated user could cause another user to perform unwanted actions within the application they are logged into. This vulnerability is possible due to the lack of proper CSRF token implementation. Among other things, it is possible, using a POST request to delete all commands via '/delete_all_commands?sid='.
Metrics
Affected Vendors & Products
References
History
Wed, 28 Jan 2026 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 28 Jan 2026 12:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Cross-Site request forgery (CSRF) vulnerability in Sync Breeze Enterprise Server v10.4.18 and Disk Pulse Enterprise v10.4.18. An authenticated user could cause another user to perform unwanted actions within the application they are logged into. This vulnerability is possible due to the lack of proper CSRF token implementation. Among other things, it is possible, using a POST request to delete all commands via '/delete_all_commands?sid='. | |
| Title | Cross-Site request forgery (CSRF) vulnerability in Sync Breeze Enterprise Server | |
| First Time appeared |
Flexense
Flexense disk Pulse Enterprise Flexense sync Breeze Enterprise Server |
|
| Weaknesses | CWE-352 | |
| CPEs | cpe:2.3:a:flexense:disk_pulse_enterprise:v10.4.18:*:*:*:*:*:*:* cpe:2.3:a:flexense:sync_breeze_enterprise_server:v10.4.18:*:*:*:*:*:*:* |
|
| Vendors & Products |
Flexense
Flexense disk Pulse Enterprise Flexense sync Breeze Enterprise Server |
|
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: INCIBE
Published: 2026-01-28T11:53:24.197Z
Updated: 2026-01-28T15:40:28.684Z
Reserved: 2025-09-23T10:22:34.912Z
Link: CVE-2025-59894
Updated: 2026-01-28T15:40:23.552Z
Status : Received
Published: 2026-01-28T12:15:50.960
Modified: 2026-01-28T12:15:50.960
Link: CVE-2025-59894
No data.