CWE-639: Authorization Bypass Through User-Controlled Key in web services in Progress Sitefinity 15.2.x before 15.2.8441, 15.3.x before 15.3.8531, and 15.4.x before 15.4.8630 allows a remote authenticated attacker to modify account properties of other users, potentially leading to account compromise. Successful exploitation requires knowledge of values that are not generally exposed to low-privileged users.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 15.2.8400, < 15.2.8441CPE match | cpe:2.3:a:progress:sitefinity:*:*:*:*:*:*:*:* | ||
>= 15.3.8500, < 15.3.8531CPE match | cpe:2.3:a:progress:sitefinity:*:*:*:*:*:*:*:* | ||
>= 15.4.8600, < 15.4.8630CPE match | cpe:2.3:a:progress:sitefinity:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.