Progress Sitefinity是美国Progress公司的一套开源的用于构建企业网站以及企业内部网络的平台。 Progress Sitefinity 15.4.8623至15.4.8630之前版本存在访问控制错误漏洞,该漏洞源于Web服务中访问控制不当,可能导致远程未经身份验证的攻击者访问受限内容。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Progress Software | Sitefinity | 15.4.8623< 15.4.8630 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Progress Software | Sitefinity | 15.4.8623 ~ 15.4.8630 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-7312 | 10.0 CRITICAL | CWE‑522: Insufficiently Protected Credentials in web services in Progress Sitefinity |
| CVE-2026-7195 | 8.8 HIGH | CWE-20: Improper Input Validation in web services in Progress Sitefinity |
| CVE-2026-7201 | 8.8 HIGH | CWE-639: Authorization Bypass Through User-Controlled Key in web services in Progress Site |
| CVE-2026-7313 | 8.7 HIGH | CWE‑522: Insufficiently Protected Credentials in web services in Progress Sitefinity |
No comments yet