← Back

CVE-2019-7215

nvd nist
Published: Jun 6, 2019Modified: Jun 17, 2026

JSON object

Loading...
6.5
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
Exploitability: 3.9 / Impact: 2.5
Source: NVD

Description

Progress Sitefinity 10.1.6536 does not invalidate session cookies upon logouts. It instead tries to overwrite the cookie in the browser, but it remains valid on the server side. This means the cookie can be reused to maintain access to the account, even if the account credentials and permissions are changed.

Affected (16)

Products: Progress: Sitefinity
1 product
Sitefinity
Configuration A
16 vulnerable
Vulnerable SoftwareAffected Versions
Progress
From 10.0 to 10.0.6429
From 10.1 to 10.1.6540
From 10.2 to 10.2.6649
From 11.0 to 11.0.6736
From 11.1 to 11.1.6826
From 11.2 to 11.2.6929
From 7.0 to 7.0.5143
From 7.1 to 7.1.5243
From 7.2 to 7.2.5353
From 7.3 to 7.3.5693
From 8.0 to 8.0.5773
From 8.1 to 8.1.5863
From 8.2 to 8.2.5973
From 9.0 to 9.0.6063
From 9.1 to 9.1.6183
From 9.2 to 9.2.6274

Timeline

No history available yet.