Sitefinity 5.1, 5.2, 5.3, 5.4, 6.x, 7.x, 8.x, 9.x, and 10.x allow remote attackers to bypass authentication and consequently cause a denial of service on load balanced sites or gain privileges via vectors related to weak cryptography.
References
Link | Resource |
---|---|
https://www.mnemonic.no/news/2017/vulnerability-finding-sitefinity-cms/ | Third Party Advisory |
https://knowledgebase.progress.com/articles/Article/Sitefinity-Security-Advisory-for-cryptographic-vulnerability-CVE-2017-15883 | Vendor Advisory |
Configurations
Configuration 1 (hide)
|
Information
Published : 2018-01-08 11:29
Updated : 2018-02-01 11:53
NVD link : CVE-2017-15883
Mitre link : CVE-2017-15883
JSON object : View
CWE
CWE-287
Improper Authentication
Products Affected
progress
- sitefinity