Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-28j7-fpg4-34hj

Опубликовано: 02 июн. 2026
Источник: github
Github: Не прошло ревью
CVSS3: 8.7

Описание

CWE‑522: Insufficiently Protected Credentials in web services in Progress Sitefinity version from 8.0.5700 to 13.3.7652 allows a remote authenticated attacker to obtain plain-text credentials used connect to Sitefinity Insight service. Successful exploitation requires active integration with Sitefinity Insight, non-default site configuration and valid back-end authorization.

CWE‑522: Insufficiently Protected Credentials in web services in Progress Sitefinity version from 8.0.5700 to 13.3.7652 allows a remote authenticated attacker to obtain plain-text credentials used connect to Sitefinity Insight service. Successful exploitation requires active integration with Sitefinity Insight, non-default site configuration and valid back-end authorization.

EPSS

Процентиль: 24%
0.00319
Низкий

8.7 High

CVSS3

Дефекты

CWE-522

Связанные уязвимости

CVSS3: 8.7
nvd
2 месяца назад

CWE‑522: Insufficiently Protected Credentials in web services in Progress Sitefinity version from 8.0.5700 to 13.3.7652 allows a remote authenticated attacker to obtain plain-text credentials used connect to Sitefinity Insight service. Successful exploitation requires active integration with Sitefinity Insight, non-default site configuration and valid back-end authorization.

EPSS

Процентиль: 24%
0.00319
Низкий

8.7 High

CVSS3

Дефекты

CWE-522