CVE-2024-11627: High severity progress vulnerability
: Insufficient Session Expiration vulnerability in Progress Sitefinity allows : Session Fixation.This issue affects Sitefinity: from 4.0 through 14.4.8142, from 15.0.8200 through 15.0.8229, from 15.1.8300 through 15.1.8327, from 15.2.8400 through 15.2.8421.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-11627?
CVE-2024-11627 is classified with a high severity due to the potential for session fixation attacks.
How do I fix CVE-2024-11627?
To mitigate CVE-2024-11627, update Progress Sitefinity to the latest version that addresses the session expiration vulnerability.
Which versions of Progress Sitefinity are affected by CVE-2024-11627?
CVE-2024-11627 affects Progress Sitefinity versions from 4.0 to 14.4.8142, and several versions between 15.0.8200 and 15.2.8421.
What type of vulnerability is CVE-2024-11627?
CVE-2024-11627 is an Insufficient Session Expiration vulnerability that enables session fixation.
Is there a risk of exploitation with CVE-2024-11627?
Yes, CVE-2024-11627 poses a significant risk as it allows attackers to exploit session fixation vulnerabilities.