Progress Sitefinity
cpe:2.3:a:progress:sitefinity:*:*:*:*:*:*:*, +1 more
- >= 4.0, <= 14.4.8142
- >= 15.0.8200, <= 15.0.8229
- >= 15.1.8300, <= 15.1.8327
- >= 15.2.8400, <= 15.2.8421
A session fixation vulnerability has been identified in Progress Sitefinity, stemming from insufficient session expiration. This issue affects Sitefinity versions 4.0 through 14.4.8142, 15.0.8200 through 15.0.8229, 15.1.8300 through 15.1.8327, and 15.2.8400 through 15.2.8421.
Exploitation of this vulnerability allows for session fixation, where an attacker can manipulate a user's session ID, potentially leading to unauthorized access or actions within the application.
Progress has released patches for all supported versions. Sitefinity customers are advised to update to version 15.2.8422, 15.1.8328, 15.0.8230 or 14.4.8143. For instructions on applying the update, refer to the Sitefinity patch update guide.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.