Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-7195

Опубликовано: 02 июн. 2026
Источник: nvd
CVSS3: 8.8
CVSS3: 8.1
EPSS Низкий

Описание

CWE-20: Improper Input Validation in web services in Progress Sitefinity 14.1.x through 14.3.x, 14.4.x before 14.4.8152, 15.0.x before 15.0.8234, 15.1.x before 15.1.8335, 15.2.x before 15.2.8441, 15.3.x before 15.3.8531, and 15.4.x before 15.4.8630 allows a remote unauthenticated attacker to compromise the integrity and confidentiality of user accounts. Successful exploitation requires user interaction and a non-default site configuration.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:progress:sitefinity:*:*:*:*:*:*:*:*
Версия от 14.1.7800 (включая) до 14.4.8152 (исключая)
cpe:2.3:a:progress:sitefinity:*:*:*:*:*:*:*:*
Версия от 15.0.8200 (включая) до 15.0.8234 (исключая)
cpe:2.3:a:progress:sitefinity:*:*:*:*:*:*:*:*
Версия от 15.1.8300 (включая) до 15.1.8335 (исключая)
cpe:2.3:a:progress:sitefinity:*:*:*:*:*:*:*:*
Версия от 15.2.8400 (включая) до 15.2.8441 (исключая)
cpe:2.3:a:progress:sitefinity:*:*:*:*:*:*:*:*
Версия от 15.3.8500 (включая) до 15.3.8531 (исключая)
cpe:2.3:a:progress:sitefinity:*:*:*:*:*:*:*:*
Версия от 15.4.8600 (включая) до 15.4.8630 (исключая)

EPSS

Процентиль: 37%
0.00471
Низкий

8.8 High

CVSS3

8.1 High

CVSS3

Дефекты

CWE-20

Связанные уязвимости

CVSS3: 8.8
github
2 месяца назад

CWE-20: Improper Input Validation in web services in Progress Sitefinity 14.1.x through 14.3.x, 14.4.x before 14.4.8152, 15.0.x before 15.0.8234, 15.1.x before 15.1.8335, 15.2.x before 15.2.8441, 15.3.x before 15.3.8531, and 15.4.x before 15.4.8630 allows a remote unauthenticated attacker to compromise the integrity and confidentiality of user accounts. Successful exploitation requires user interaction and a non-default site configuration.

EPSS

Процентиль: 37%
0.00471
Низкий

8.8 High

CVSS3

8.1 High

CVSS3

Дефекты

CWE-20