Lucene search

K
cveMitreCVE-2023-29375
HistoryApr 10, 2023 - 3:15 p.m.

CVE-2023-29375

2023-04-1015:15:07
CWE-434
mitre
web.nvd.nist.gov
22
progress sitefinity
file upload
sharepoint
security issue
cve-2023-29375

CVSS3

9.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

AI Score

9.4

Confidence

High

EPSS

0.002

Percentile

59.9%

An issue was discovered in Progress Sitefinity 13.3 before 13.3.7647, 14.0 before 14.0.7736, 14.1 before 14.1.7826, 14.2 before 14.2.7930, and 14.3 before 14.3.8025. There is potentially dangerous file upload through the SharePoint connector.

Affected configurations

Nvd
Node
progresssitefinityRange13.313.3.7646
OR
progresssitefinityRange14.014.0.7736
OR
progresssitefinityRange14.114.1.7826
OR
progresssitefinityRange14.214.2.7930
OR
progresssitefinityRange14.314.3.8026
VendorProductVersionCPE
progresssitefinity*cpe:2.3:a:progress:sitefinity:*:*:*:*:*:*:*:*

CVSS3

9.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

AI Score

9.4

Confidence

High

EPSS

0.002

Percentile

59.9%

Related for CVE-2023-29375