CVE-2024-1632: Incorrect access control in the Sitefinity backend
Published Feb 28, 2024
·Updated
Low-privileged users with access to the Sitefinity backend may obtain sensitive information from the site's administrative area.
Affected Software
3 affected components
Progress Sitefinity<13.3.7649
Progress Sitefinity>=14.0<14.4.8135
Progress Sitefinity>=15.0.8200<15.0.8227
Event History
Feb 28, 2024
CVE Published
via MITRE·12:04 PM
Data Sourced
via MITRE·12:04 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·12:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-1632?
CVE-2024-1632 has been classified with a low severity level.
2
How do I fix CVE-2024-1632?
To fix CVE-2024-1632, it is recommended to update the Progress Sitefinity software to the latest version.
3
Who is affected by CVE-2024-1632?
CVE-2024-1632 affects low-privileged users who have access to the Sitefinity backend.
4
What type of data can be accessed due to CVE-2024-1632?
CVE-2024-1632 allows low-privileged users to access sensitive information from the administrative area of Sitefinity.
5
Which versions of Sitefinity are impacted by CVE-2024-1632?
CVE-2024-1632 impacts Progress Sitefinity versions up to 13.3.7649, as well as all versions between 14.0 and 14.4.8135 and between 15.0.8200 and 15.0.8227.