First published: Wed Dec 20 2023(Updated: )
A malicious user could potentially use the Sitefinity system for the distribution of phishing emails.
Credit: security@progress.com
Affected Software | Affected Version | How to fix |
---|---|---|
Progress | >=4.0<13.3.7648 | |
Progress | >=14.1<14.1.7828 | |
Progress | >=14.2<14.2.7932 | |
Progress | >=14.3<14.3.8029 | |
Progress | >=14.4<14.4.8133 | |
Progress | >=15.0<15.0.8223 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-6784 is classified as a high severity vulnerability due to its potential for misuse in distributing phishing emails.
To fix CVE-2023-6784, it is recommended to update your Progress Sitefinity to the latest version available.
CVE-2023-6784 affects Progress Sitefinity versions from 4.0 to 13.3.7648 and any version from 14.1.0 to 15.0.8223.
Yes, CVE-2023-6784 can potentially be exploited remotely by a malicious user.
Failing to address CVE-2023-6784 can lead to your Sitefinity system being used for phishing attacks, posing risk to your users.