Progress Sitefinity是美国Progress公司的一套开源的用于构建企业网站以及企业内部网络的平台。 Progress Sitefinity 14.0.7700至14.4.8152版本、15.0.8200至15.0.8234版本、15.1.8300至15.1.8335版本、15.2.8400至15.2.8441版本、15.3.8500至15.3.8531版本和15.4.8600至15.4.8630版本存在安全漏洞,该漏洞源于凭据保护不足,可能导致远程未经身份验证的攻击者获取明文凭据。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Progress Software | Sitefinity | 14.0.7700< 14.4.8152 |
affected |
15.0.8200< 15.0.8234 |
affected | ||
15.1.8300< 15.1.8335 |
affected | ||
15.2.8400< 15.2.8441 |
affected | ||
15.3.8500< 15.3.8531 |
affected | ||
15.4.8600< 15.4.8630 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Progress Software | Sitefinity | 14.0.7700 ~ 14.4.8152 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-7198 | 9.8 CRITICAL | CWE-284: Improper Access Control in web services in Progress Sitefinity |
| CVE-2026-7195 | 8.8 HIGH | CWE-20: Improper Input Validation in web services in Progress Sitefinity |
| CVE-2026-7201 | 8.8 HIGH | CWE-639: Authorization Bypass Through User-Controlled Key in web services in Progress Site |
| CVE-2026-7313 | 8.7 HIGH | CWE‑522: Insufficiently Protected Credentials in web services in Progress Sitefinity |
No comments yet