Progress Sitefinity是美国Progress公司的一套开源的用于构建企业网站以及企业内部网络的平台。 Progress Sitefinity 14.1.x至14.3.x版本、14.4.8152之前版本、15.0.8234之前版本、15.1.8335之前版本、15.2.8441之前版本、15.3.8531之前版本和15.4.8630之前版本存在输入验证错误漏洞,该漏洞源于Web服务中输入验证不当,可能导致远程未经身份验证的攻击者破坏用户账户的完整性和机密性。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Progress Software | Sitefinity | 14.1.0< 14.4.0 |
affected |
14.4.8100< 14.4.8152 |
affected | ||
15.0.8200< 15.0.8234 |
affected | ||
15.1.8300< 15.1.8335 |
affected | ||
15.2.8400< 15.2.8441 |
affected | ||
15.3.8500< 15.3.8531 |
affected | ||
15.4.8600< 15.4.8630 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Progress Software | Sitefinity | 14.1.0 ~ 14.4.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-7312 | 10.0 CRITICAL | CWE‑522: Insufficiently Protected Credentials in web services in Progress Sitefinity |
| CVE-2026-7198 | 9.8 CRITICAL | CWE-284: Improper Access Control in web services in Progress Sitefinity |
| CVE-2026-7201 | 8.8 HIGH | CWE-639: Authorization Bypass Through User-Controlled Key in web services in Progress Site |
| CVE-2026-7313 | 8.7 HIGH | CWE‑522: Insufficiently Protected Credentials in web services in Progress Sitefinity |
No comments yet