CVE-2019-17392
CRITICAL
9.8
CVSS Severity Score
Vulnerability Description
Progress Sitefinity 12.1 has a Weak Password Recovery Mechanism for a Forgotten Password because the HTTP Host header is mishandled.
Affected Platforms (CPE)
📦
Progress
Sitefinity
>= 9.1 and < 9.1.6185📦
Progress
Sitefinity
>= 9.2 and < 9.2.6276📦
Progress
Sitefinity
>= 10.0 and < 10.0.6431📦
Progress
Sitefinity
>= 10.1 and < 10.1.6542📦
Progress
Sitefinity
>= 10.2 and <= 10.2.6651📦
Progress
Sitefinity
>= 11.0 and <= 11.0.6739📦
Progress
Sitefinity
>= 11.1 and <= 11.1.6828📦
Progress
Sitefinity
>= 11.2 and <= 11.2.6934📦
Progress
Sitefinity
>= 12.0 and <= 12.0.7032📦
Progress
