First published: Tue Jan 07 2025(Updated: )
: Insufficient Session Expiration vulnerability in Progress Sitefinity allows : Session Fixation.This issue affects Sitefinity: from 4.0 through 14.4.8142, from 15.0.8200 through 15.0.8229, from 15.1.8300 through 15.1.8327, from 15.2.8400 through 15.2.8421.
Credit: security@progress.com
Affected Software | Affected Version | How to fix |
---|---|---|
Progress | >=4.0<=14.4.8142>=15.0.8200<15.0.8229>=15.1.8300<15.1.8327>=15.2.8400<15.2.8421 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-11627 is classified with a high severity due to the potential for session fixation attacks.
To mitigate CVE-2024-11627, update Progress Sitefinity to the latest version that addresses the session expiration vulnerability.
CVE-2024-11627 affects Progress Sitefinity versions from 4.0 to 14.4.8142, and several versions between 15.0.8200 and 15.2.8421.
CVE-2024-11627 is an Insufficient Session Expiration vulnerability that enables session fixation.
Yes, CVE-2024-11627 poses a significant risk as it allows attackers to exploit session fixation vulnerabilities.