CyberSec.Space Logo
Back to CVE Browser

CVE-2019-17392

CRITICAL
9.8
CVSS Severity Score
EPSS Score0.0280%
EPSS Percentile39.11th
PublishedNov 26, 2019
Last ModifiedNov 21, 2024

Vulnerability Description

Progress Sitefinity 12.1 has a Weak Password Recovery Mechanism for a Forgotten Password because the HTTP Host header is mishandled.

Affected Platforms (CPE)

πŸ“¦
Progress

Sitefinity

>= 9.1 and < 9.1.6185
πŸ“¦
Progress

Sitefinity

>= 9.2 and < 9.2.6276
πŸ“¦
Progress

Sitefinity

>= 10.0 and < 10.0.6431
πŸ“¦
Progress

Sitefinity

>= 10.1 and < 10.1.6542
πŸ“¦
Progress

Sitefinity

>= 10.2 and <= 10.2.6651
πŸ“¦
Progress

Sitefinity

>= 11.0 and <= 11.0.6739
πŸ“¦
Progress

Sitefinity

>= 11.1 and <= 11.1.6828
πŸ“¦
Progress

Sitefinity

>= 11.2 and <= 11.2.6934
πŸ“¦
Progress

Sitefinity

>= 12.0 and <= 12.0.7032
πŸ“¦
Progress

Sitefinity

>= 12.1 and <= 12.1.7128

References & Advisories

Related Vulnerabilities