CVE-2025-13774

EUVD-2026-2350
A vulnerability exists in Progress Flowmon ADS versions prior to 12.5.4 and 13.0.1 where an SQL injection vulnerability allows authenticated users to execute unintended SQL queries and commands.
SQL Injection
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
8.8 HIGH
NETWORK
LOW
LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: Unknown
Affected Products (NVD)
VendorProductVersion
progressflowmon_anomaly_detection_system
12.0.0 ≤
𝑥
≤ 12.5.4
progressflowmon_anomaly_detection_system
13.0.0 ≤
𝑥
≤ 13.0.1
𝑥
= Vulnerable software versions