CVE-2023-6784: Potential Use of the Sitefinity System for Distribution of Phishing Emails
Published Dec 20, 2023
·Updated
A malicious user could potentially use the Sitefinity system for the distribution of phishing emails.
Affected Software
6 affected components
Progress Sitefinity>=4.0<13.3.7648
Progress Sitefinity>=14.1<14.1.7828
Progress Sitefinity>=14.2<14.2.7932
Progress Sitefinity>=14.3<14.3.8029
Progress Sitefinity>=14.4<14.4.8133
Progress Sitefinity>=15.0<15.0.8223
Event History
Dec 20, 2023
CVE Published
02:00 PM
Data Sourced
02:00 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2023-6784?
CVE-2023-6784 is classified as a high severity vulnerability due to its potential for misuse in distributing phishing emails.
2
How do I fix CVE-2023-6784?
To fix CVE-2023-6784, it is recommended to update your Progress Sitefinity to the latest version available.
3
Which versions of Progress Sitefinity are affected by CVE-2023-6784?
CVE-2023-6784 affects Progress Sitefinity versions from 4.0 to 13.3.7648 and any version from 14.1.0 to 15.0.8223.
4
Can CVE-2023-6784 be exploited remotely?
Yes, CVE-2023-6784 can potentially be exploited remotely by a malicious user.
5
What are the implications of not addressing CVE-2023-6784?
Failing to address CVE-2023-6784 can lead to your Sitefinity system being used for phishing attacks, posing risk to your users.