CVE-2023-26100: Progress Flowmon OS
Medium severity, CVSS 6.1. EPSS: 0.4% chance of exploitation in the next 30 days.
In Progress Flowmon before 12.2.0, an application endpoint failed to sanitize user-supplied input. A threat actor could leverage a reflected XSS vulnerability to execute arbitrary code within the context of a Flowmon user's web browser.
Affected products
- Progress Flowmon OS: before 12.2.0 (fixed in 12.2.0)
Published 2023-04-21. Last modified 2026-06-17.