CVE-2019-17392
26.11.2019, 18:15
Progress Sitefinity 12.1 has a Weak Password Recovery Mechanism for a Forgotten Password because the HTTP Host header is mishandled.Enginsight
Vendor | Product | Version |
---|---|---|
progress | sitefinity | 9.1 ≤ 𝑥 < 9.1.6185 |
progress | sitefinity | 9.2 ≤ 𝑥 < 9.2.6276 |
progress | sitefinity | 10.0 ≤ 𝑥 < 10.0.6431 |
progress | sitefinity | 10.1 ≤ 𝑥 < 10.1.6542 |
progress | sitefinity | 10.2 ≤ 𝑥 ≤ 10.2.6651 |
progress | sitefinity | 11.0 ≤ 𝑥 ≤ 11.0.6739 |
progress | sitefinity | 11.1 ≤ 𝑥 ≤ 11.1.6828 |
progress | sitefinity | 11.2 ≤ 𝑥 ≤ 11.2.6934 |
progress | sitefinity | 12.0 ≤ 𝑥 ≤ 12.0.7032 |
progress | sitefinity | 12.1 ≤ 𝑥 ≤ 12.1.7128 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration