Critical severity9.8NVD Advisory· Published Nov 26, 2019· Updated Jun 17, 2026
CVE-2019-17392
CVE-2019-17392
Description
Progress Sitefinity 12.1 has a Weak Password Recovery Mechanism for a Forgotten Password because the HTTP Host header is mishandled.
Affected products
3cpe:2.3:a:progress:sitefinity:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:progress:sitefinity:*:*:*:*:*:*:*:*range: >=9.1,<9.1.6185
- (no CPE)range: <12.1
- Progress/Progress Sitefinitydescription
Patches
Vulnerability mechanics
References
1News mentions
0No linked articles in our index yet.