Sitefinity 5.1, 5.2, 5.3, 5.4, 6.x, 7.x, 8.x, 9.x, and 10.x allow remote attackers to bypass authentication and consequently cause a denial of service on load balanced sites or gain privileges via vectors related to weak cryptography.
References
Configurations
Configuration 1 (hide)
|
History
21 Nov 2024, 03:15
Type | Values Removed | Values Added |
---|---|---|
References | () https://knowledgebase.progress.com/articles/Article/Sitefinity-Security-Advisory-for-cryptographic-vulnerability-CVE-2017-15883 - Vendor Advisory | |
References | () https://www.mnemonic.no/news/2017/vulnerability-finding-sitefinity-cms/ - Third Party Advisory |
Information
Published : 2018-01-08 19:29
Updated : 2024-11-21 03:15
NVD link : CVE-2017-15883
Mitre link : CVE-2017-15883
CVE.ORG link : CVE-2017-15883
JSON object : View
Products Affected
progress
- sitefinity
CWE
CWE-287
Improper Authentication