Progress Sitefinity是美国Progress公司的一套开源的用于构建企业网站以及企业内部网络的平台。 Progress Sitefinity 15.2.8441之前版本、15.3.8531之前版本和15.4.8630之前版本存在安全漏洞,该漏洞源于Web服务中通过用户控制密钥的授权绕过,可能导致远程经过身份验证的攻击者修改其他用户的账户属性。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Progress Software | Sitefinity | 15.2.8400< 15.2.8441 |
affected |
15.3.8500< 15.3.8531 |
affected | ||
15.4.8600< 15.4.8630 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Progress Software | Sitefinity | 15.2.8400 ~ 15.2.8441 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-7312 | 10.0 CRITICAL | CWE‑522: Insufficiently Protected Credentials in web services in Progress Sitefinity |
| CVE-2026-7198 | 9.8 CRITICAL | CWE-284: Improper Access Control in web services in Progress Sitefinity |
| CVE-2026-7195 | 8.8 HIGH | CWE-20: Improper Input Validation in web services in Progress Sitefinity |
| CVE-2026-7313 | 8.7 HIGH | CWE‑522: Insufficiently Protected Credentials in web services in Progress Sitefinity |
No comments yet