CyberSec.Space Logo
CVEブラウザに戻る

CVE-2019-17392

CRITICAL
9.8
CVSS Severity Score
EPSS Score0.0280%
EPSS Percentile39.11th
Published2019年11月26日
Last Modified2024年11月21日

Vulnerability Description

Progress Sitefinity 12.1 has a Weak Password Recovery Mechanism for a Forgotten Password because the HTTP Host header is mishandled.

Affected Platforms (CPE)

📦
Progress

Sitefinity

>= 9.1 and < 9.1.6185
📦
Progress

Sitefinity

>= 9.2 and < 9.2.6276
📦
Progress

Sitefinity

>= 10.0 and < 10.0.6431
📦
Progress

Sitefinity

>= 10.1 and < 10.1.6542
📦
Progress

Sitefinity

>= 10.2 and <= 10.2.6651
📦
Progress

Sitefinity

>= 11.0 and <= 11.0.6739
📦
Progress

Sitefinity

>= 11.1 and <= 11.1.6828
📦
Progress

Sitefinity

>= 11.2 and <= 11.2.6934
📦
Progress

Sitefinity

>= 12.0 and <= 12.0.7032
📦
Progress

Sitefinity

>= 12.1 and <= 12.1.7128

References & Advisories

関連する脆弱性情報