CVE-2025-59891 | Flexense Sync Breeze Enterprise Server 10.4.18 POST Request /setup_login username/password/cpassword cross-site request forgery
A vulnerability marked as problematic has been reported in Flexense Sync Breeze Enterprise Server and Disk Pulse Enterprise 10.4.18. The impacted element is an unknown function of the file /setup_login of the component POST Request Handler. This manipulation of the argument username/password/cpassword causes cross-site request forgery.
This vulnerability is tracked as CVE-2025-59891. The attack is possible to be carried out remotely. No exploit exists.