CVE-2024-11627
CVSS 3.1 Score 6.8 of 10 (medium)
Details
Summary
CVE-2024-11627 is a session expiration vulnerability affecting Progress Sitefinity from versions 4.0 to 15.2.8421. This issue enables session fixation, allowing an attacker to manipulate a user's session without their knowledge. The vulnerability impacts Sitefinity versions from 4.0 through 14.4.8142, from 15.0.8200 to 15.0.8229, and from 15.1.8300 to 15.1.8327, as well as from 15.2.8400 to 15.2.8421. This security flaw can lead to unauthorized access to user accounts and sensitive data. Users are advised to upgrade to the latest, secure version of Sitefinity to mitigate this risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- Progress SiteFinity
Affected Vendors
- Progress Publishers