CVE-2019-7215
Last modified
CVE-2019-7215 is a vulnerability of currently unknown severity. Progress Sitefinity 10.1.6536 does not invalidate session cookies upon logouts. It instead tries to overwrite the cookie in the browser, but it remains valid on the server side. EPSS estimates a 0.93% chance of exploitation in the next 30 days.
Description
Progress Sitefinity 10.1.6536 does not invalidate session cookies upon logouts. It instead tries to overwrite the cookie in the browser, but it remains valid on the server side. This means the cookie can be reused to maintain access to the account, even if the account credentials and permissions are changed.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Progress | Sitefinity | >= 7.0, < 7.0.5143 |
| Progress | Sitefinity | >= 7.1, < 7.1.5243 |
| Progress | Sitefinity | >= 7.2, < 7.2.5353 |
| Progress | Sitefinity | >= 7.3, < 7.3.5693 |
| Progress | Sitefinity | >= 8.0, < 8.0.5773 |
| Progress | Sitefinity | >= 8.1, < 8.1.5863 |
| Progress | Sitefinity | >= 8.2, < 8.2.5973 |
| Progress | Sitefinity | >= 9.0, < 9.0.6063 |
| Progress | Sitefinity | >= 9.1, < 9.1.6183 |
| Progress | Sitefinity | >= 9.2, < 9.2.6274 |
| Progress | Sitefinity | >= 10.0, < 10.0.6429 |
| Progress | Sitefinity | >= 10.1, <= 10.1.6540 |
| Progress | Sitefinity | >= 10.2, < 10.2.6649 |
| Progress | Sitefinity | >= 11.0, < 11.0.6736 |
| Progress | Sitefinity | >= 11.1, < 11.1.6826 |
| Progress | Sitefinity | >= 11.2, < 11.2.6929 |
References
- https://knowledgebase.progress.com/articles/Article/Security-Advisory-For-Resolving-Security-Vulnerabilities-May-2019Release Notes, Vendor Advisory
- https://knowledgebase.progress.com/articles/Article/Security-Advisory-For-Resolving-Security-Vulnerabilities-May-2019Release Notes, Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2019-7215?
How severe is CVE-2019-7215?
How do I fix CVE-2019-7215?
Are you affected by CVE-2019-7215?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
