CVE-2019-7215

Progress Sitefinity 10.1.6536 does not invalidate session cookies upon logouts. It instead tries to overwrite the cookie in the browser, but it remains valid on the server side. This means the cookie can be reused to maintain access to the account, even if the account credentials and permissions are changed.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
6.5 MEDIUM
NETWORK
LOW
NONE
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
mitreCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: Unknown
VendorProductVersion
progresssitefinity
7.0 ≤
𝑥
< 7.0.5143
progresssitefinity
7.1 ≤
𝑥
< 7.1.5243
progresssitefinity
7.2 ≤
𝑥
< 7.2.5353
progresssitefinity
7.3 ≤
𝑥
< 7.3.5693
progresssitefinity
8.0 ≤
𝑥
< 8.0.5773
progresssitefinity
8.1 ≤
𝑥
< 8.1.5863
progresssitefinity
8.2 ≤
𝑥
< 8.2.5973
progresssitefinity
9.0 ≤
𝑥
< 9.0.6063
progresssitefinity
9.1 ≤
𝑥
< 9.1.6183
progresssitefinity
9.2 ≤
𝑥
< 9.2.6274
progresssitefinity
10.0 ≤
𝑥
< 10.0.6429
progresssitefinity
10.1 ≤
𝑥
≤ 10.1.6540
progresssitefinity
10.2 ≤
𝑥
< 10.2.6649
progresssitefinity
11.0 ≤
𝑥
< 11.0.6736
progresssitefinity
11.1 ≤
𝑥
< 11.1.6826
progresssitefinity
11.2 ≤
𝑥
< 11.2.6929
𝑥
= Vulnerable software versions