CVE-2019-17392

Severity CVSS v4.0:
Pending analysis
Type:
CWE-640 Weak Password Recovery Mechanism for Forgotten Password
Publication date:
26/11/2019
Last modified:
14/12/2019

Description

Progress Sitefinity 12.1 has a Weak Password Recovery Mechanism for a Forgotten Password because the HTTP Host header is mishandled.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:progress:sitefinity:*:*:*:*:*:*:*:* 9.1 (including) 9.1.6185 (excluding)
cpe:2.3:a:progress:sitefinity:*:*:*:*:*:*:*:* 9.2 (including) 9.2.6276 (excluding)
cpe:2.3:a:progress:sitefinity:*:*:*:*:*:*:*:* 10.0 (including) 10.0.6431 (excluding)
cpe:2.3:a:progress:sitefinity:*:*:*:*:*:*:*:* 10.1 (including) 10.1.6542 (excluding)
cpe:2.3:a:progress:sitefinity:*:*:*:*:*:*:*:* 10.2 (including) 10.2.6651 (including)
cpe:2.3:a:progress:sitefinity:*:*:*:*:*:*:*:* 11.0 (including) 11.0.6739 (including)
cpe:2.3:a:progress:sitefinity:*:*:*:*:*:*:*:* 11.1 (including) 11.1.6828 (including)
cpe:2.3:a:progress:sitefinity:*:*:*:*:*:*:*:* 11.2 (including) 11.2.6934 (including)
cpe:2.3:a:progress:sitefinity:*:*:*:*:*:*:*:* 12.0 (including) 12.0.7032 (including)
cpe:2.3:a:progress:sitefinity:*:*:*:*:*:*:*:* 12.1 (including) 12.1.7128 (including)