CVE-2024-11627

CVSS 3.1 Score 6.8 of 10 (medium)

Details

Published Jan 7, 2025
CWE ID 613

Summary

CVE-2024-11627 is a session expiration vulnerability affecting Progress Sitefinity from versions 4.0 to 15.2.8421. This issue enables session fixation, allowing an attacker to manipulate a user's session without their knowledge. The vulnerability impacts Sitefinity versions from 4.0 through 14.4.8142, from 15.0.8200 to 15.0.8229, and from 15.1.8300 to 15.1.8327, as well as from 15.2.8400 to 15.2.8421. This security flaw can lead to unauthorized access to user accounts and sensitive data. Users are advised to upgrade to the latest, secure version of Sitefinity to mitigate this risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Affected Products

  • Progress SiteFinity

Affected Vendors

  • Progress Publishers