CVE-2019-7215: Medium severity progress vulnerability
Progress Sitefinity 10.1.6536 does not invalidate session cookies upon logouts. It instead tries to overwrite the cookie in the browser, but it remains valid on the server side. This means the cookie can be reused to maintain access to the account, even if the account credentials and permissions are changed.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2019-7215?
CVE-2019-7215 is a vulnerability in Progress Sitefinity 10.1.6536 that allows session cookies to remain valid on the server side even after logout.
How does CVE-2019-7215 affect Progress Sitefinity?
CVE-2019-7215 affects Progress Sitefinity versions 10.1.6536 and earlier by not invalidating session cookies upon logouts.
What is the severity of CVE-2019-7215?
The severity of CVE-2019-7215 is medium with a CVSS score of 6.5.
How can I fix CVE-2019-7215?
To fix CVE-2019-7215, it is recommended to update to a version of Progress Sitefinity that is not affected by the vulnerability.
Where can I find more information about CVE-2019-7215?
More information about CVE-2019-7215 can be found in the Progress Knowledge Base.