VYPR
Critical severity9.8NVD Advisory· Published Nov 26, 2019· Updated Jun 17, 2026

CVE-2019-17392

CVE-2019-17392

Description

Progress Sitefinity 12.1 has a Weak Password Recovery Mechanism for a Forgotten Password because the HTTP Host header is mishandled.

Affected products

3
  • cpe:2.3:a:progress:sitefinity:*:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:progress:sitefinity:*:*:*:*:*:*:*:*range: >=9.1,<9.1.6185
    • (no CPE)range: <12.1
  • Progress/Progress Sitefinitydescription

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.