CVE-2019-17392: Progress Sitefinity

Critical severity, CVSS 9.8. EPSS: 1.1% chance of exploitation in the next 30 days.

Progress Sitefinity 12.1 has a Weak Password Recovery Mechanism for a Forgotten Password because the HTTP Host header is mishandled.

Affected products

  • Progress Sitefinity: from 9.1, before 9.1.6185 (fixed in 9.1.6185); from 9.2, before 9.2.6276 (fixed in 9.2.6276); from 10.0, before 10.0.6431 (fixed in 10.0.6431); from 10.1, before 10.1.6542 (fixed in 10.1.6542); from 10.2, up to and including 10.2.6651; from 11.0, up to and including 11.0.6739; …

Published 2019-11-26. Last modified 2026-06-17.