Progress Sitefinity是美国Progress公司的一套开源的用于构建企业网站以及企业内部网络的平台。 Progress Sitefinity 8.0.5700至13.3.7652版本存在安全漏洞,该漏洞源于凭据保护不足,可能导致远程经过身份验证的攻击者获取明文凭据。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Progress Software | Sitefinity | 8.0.5700< 13.3.7652 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Progress Software | Sitefinity | 8.0.5700 ~ 13.3.7652 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-7312 | 10.0 CRITICAL | CWE‑522: Insufficiently Protected Credentials in web services in Progress Sitefinity |
| CVE-2026-7198 | 9.8 CRITICAL | CWE-284: Improper Access Control in web services in Progress Sitefinity |
| CVE-2026-7195 | 8.8 HIGH | CWE-20: Improper Input Validation in web services in Progress Sitefinity |
| CVE-2026-7201 | 8.8 HIGH | CWE-639: Authorization Bypass Through User-Controlled Key in web services in Progress Site |
No comments yet