4.3

CVE-2023-6784

Potential Use of the Sitefinity System for Distribution of Phishing Emails

A malicious user could potentially use the Sitefinity system for the distribution of phishing emails.

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Progress ≫ Sitefinity Version >= 4.0 < 13.3.7648
Progress ≫ Sitefinity Version >= 14.1 < 14.1.7828
Progress ≫ Sitefinity Version >= 14.2 < 14.2.7932
Progress ≫ Sitefinity Version >= 14.3 < 14.3.8029
Progress ≫ Sitefinity Version >= 14.4 < 14.4.8133
Progress ≫ Sitefinity Version >= 15.0 < 15.0.8223
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.38% 0.296
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 4.3 2.8 1.4
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
security@progress.com 4.7 2.8 1.4
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:L/A:N
CWE-20 Improper Input Validation

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

https://www.progress.com/sitefinity-cms
Product
https://community.progress.com/s/article/Sitefinity-Security-Advisory-for-Addressing-Security-Vulnerability-CVE-2023-6784-December-2023
Vendor Advisory