← Back

CVE-2019-17392

nvd nist
Published: Nov 26, 2019Modified: Nov 21, 2024

JSON object

Loading...
9.8
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitability: 3.9 / Impact: 5.9
Source: NVD

Description

Progress Sitefinity 12.1 has a Weak Password Recovery Mechanism for a Forgotten Password because the HTTP Host header is mishandled.

Affected (10)

Products: Progress: Sitefinity
1 product
Sitefinity
Configuration A
10 vulnerable
Vulnerable SoftwareAffected Versions
Progress
From 10.0 to 10.0.6431
From 10.1 to 10.1.6542
From 10.2 to 10.2.6651
From 11.0 to 11.0.6739
From 11.1 to 11.1.6828
From 11.2 to 11.2.6934
From 12.0 to 12.0.7032
From 12.1 to 12.1.7128
From 9.1 to 9.1.6185
From 9.2 to 9.2.6276

Timeline

No history available yet.