Impact
The vulnerability in Progress Flowmon permits an authenticated low‑privileged user to manipulate the PDF generation request so that the system performs operations with the privileges of another account. This unauthorized privilege escalation can lead to sensitive data exposure and unintended modifications to system configuration, thereby compromising confidentiality, integrity, and potentially availability. The flaw arises from a breach of authorization controls, identified as CWE‑863.
Affected Systems
This flaw affects Progress Software’s Flowmon product. Versions prior to 12.5.9 in the 12.x release line and prior to 13.0.11 in the 13.x release line are vulnerable. Any deployment of these versions that has PDF generation enabled is at risk.
Risk and Exploitability
The CVSS score of 8.7 indicates high severity, reflecting a significant impact on the system. The EPSS score is <1%, indicating a very low probability of exploitation. The vulnerability is not listed in the CISA KEV catalog, suggesting no widespread exploitation to date. Exploitation requires an authenticated low‑privileged user, implying that the attack vector likely involves sending a specially crafted PDF generation request from an authenticated session. The rights‑to‑use privilege escalation is limited to contexts where PDF generation is supported and privilege rights are applicable.
OpenCVE Enrichment