CVE-2019-17392
Severity CVSS v4.0:
Pending analysis
Type:
CWE-640
Weak Password Recovery Mechanism for Forgotten Password
Publication date:
26/11/2019
Last modified:
14/12/2019
Description
Progress Sitefinity 12.1 has a Weak Password Recovery Mechanism for a Forgotten Password because the HTTP Host header is mishandled.
Impact
Base Score 3.x
9.80
Severity 3.x
CRITICAL
Base Score 2.0
7.50
Severity 2.0
HIGH
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:progress:sitefinity:*:*:*:*:*:*:*:* | 9.1 (including) | 9.1.6185 (excluding) |
| cpe:2.3:a:progress:sitefinity:*:*:*:*:*:*:*:* | 9.2 (including) | 9.2.6276 (excluding) |
| cpe:2.3:a:progress:sitefinity:*:*:*:*:*:*:*:* | 10.0 (including) | 10.0.6431 (excluding) |
| cpe:2.3:a:progress:sitefinity:*:*:*:*:*:*:*:* | 10.1 (including) | 10.1.6542 (excluding) |
| cpe:2.3:a:progress:sitefinity:*:*:*:*:*:*:*:* | 10.2 (including) | 10.2.6651 (including) |
| cpe:2.3:a:progress:sitefinity:*:*:*:*:*:*:*:* | 11.0 (including) | 11.0.6739 (including) |
| cpe:2.3:a:progress:sitefinity:*:*:*:*:*:*:*:* | 11.1 (including) | 11.1.6828 (including) |
| cpe:2.3:a:progress:sitefinity:*:*:*:*:*:*:*:* | 11.2 (including) | 11.2.6934 (including) |
| cpe:2.3:a:progress:sitefinity:*:*:*:*:*:*:*:* | 12.0 (including) | 12.0.7032 (including) |
| cpe:2.3:a:progress:sitefinity:*:*:*:*:*:*:*:* | 12.1 (including) | 12.1.7128 (including) |
To consult the complete list of CPE names with products and versions, see this page



