CVE-2024-11627

: Insufficient Session Expiration vulnerability in Progress Sitefinity allows : Session Fixation.This issue affects Sitefinity: from 4.0 through 14.4.8142, from 15.0.8200 through 15.0.8229, from 15.1.8300 through 15.1.8327,from 15.2.8400 through 15.2.8421.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
6.8 MEDIUM
NETWORK
HIGH
NONE
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:N
ProgressSoftwareCNA
6.8 MEDIUM
NETWORK
HIGH
NONE
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:N
CISA-ADPADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 8%
VendorProductVersion
progresssitefinity
4.0 ≤
𝑥
< 14.4.8143
progresssitefinity
15.0.8200 ≤
𝑥
< 15.0.8230
progresssitefinity
15.1.8300 ≤
𝑥
< 15.1.8328
progresssitefinity
15.2.8400 ≤
𝑥
< 15.2.8422
𝑥
= Vulnerable software versions