CVE-2025-1968: High severity Progress Software Sitefinity vulnerability
Insufficient Session Expiration vulnerability in Progress Software Corporation Sitefinity under some specific and uncommon circumstances allows reusing Session IDs (Session Replay Attacks).This issue affects Sitefinity: from 14.0 through 14.3, from 14.4 before 14.4.8145, from 15.0 before 15.0.8231, from 15.1 before 15.1.8332, from 15.2 before 15.2.8429.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-1968?
CVE-2025-1968 is classified as a medium severity vulnerability due to the potential for session replay attacks.
How do I fix CVE-2025-1968?
To mitigate CVE-2025-1968, ensure you update Progress Software Sitefinity to the latest versions that contain the necessary security patches.
Which versions of Sitefinity are affected by CVE-2025-1968?
CVE-2025-1968 affects Sitefinity versions 14.0 through 14.3, as well as specific older versions of 14.4, 15.0, and later.
What type of attack is related to CVE-2025-1968?
CVE-2025-1968 is associated with session replay attacks due to insufficient session expiration.
Who is impacted by CVE-2025-1968?
Organizations using affected versions of Progress Software Sitefinity are at risk of CVE-2025-1968.