CVE-2019-17392 describes a critical vulnerability in Progress Sitefinity 12.1, stemming from a weak password recovery mechanism that mishandles the HTTP Host header. This flaw carries a CVSS score of 9.8 (CRITICAL), indicating that it is easily exploitable over the network with low complexity, requiring no user interaction, and can lead to complete compromise of confidentiality, integrity, and availability. Despite its high severity and potential for significant impact, there is currently no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or community discussion surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 9.1, < 9.1.6185CPE matchmatch criteria | cpe:2.3:a:progress:sitefinity:*:*:*:*:*:*:*:* | ||
>= 9.2, < 9.2.6276CPE matchmatch criteria | cpe:2.3:a:progress:sitefinity:*:*:*:*:*:*:*:* | ||
>= 10.0, < 10.0.6431CPE matchmatch criteria | cpe:2.3:a:progress:sitefinity:*:*:*:*:*:*:*:* | ||
>= 10.1, < 10.1.6542CPE matchmatch criteria | cpe:2.3:a:progress:sitefinity:*:*:*:*:*:*:*:* | ||
>= 10.2, <= 10.2.6651CPE matchmatch criteria | cpe:2.3:a:progress:sitefinity:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.