CWE-284: Improper Access Control in web services in Progress Sitefinity 15.4.8623 before 15.4.8630 allows a remote unauthenticated attacker to access content that should be restricted, resulting in full compromise of confidentiality, integrity, and availability of affected installations.
The access control mechanism in Progress Sitefinity web services does not properly verify the requester's identity, allowing an attacker to bypass required authentication. An attacker can send requests to protected endpoints (web services) directly over the network without providing any credentials. The lack of authentication requirement (CVSS PR:N, UI:N) means that the attack does not require user interaction or possession of an account in the system.
The attacker gains full access to content and functionality that should be protected, resulting in a complete breach of confidentiality, integrity, and availability of the installed system. In practice, this may mean reading, modifying, or deleting data, as well as potential takeover of the Sitefinity installation.
Progress Sitefinity should be updated to version 15.4.8630 or newer. Detailed instructions are available in the official Progress security bulletin provided in the manufacturer's references.
Progress Sitefinity in versions 15.4.8623 to 15.4.8629 (before version 15.4.8630)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HProgress Sitefinity
APPProgress15.4.8623 – 15.4.8630 (excl.)
Related vulnerabilities
Słaba ochrona kryptograficzna w Telerik UI for ASP.NET AJAX i Sitefinity
Progress Sitefinity: ujawnienie danych uwierzytelniających w usługach web
Niebezpieczne przesyłanie plików w Progress Sitefinity przez konektor SharePoint
Słaby mechanizm odzyskiwania hasła w Progress Sitefinity 12.1
Progress Sitefinity – ominięcie uwierzytelniania przez słabą kryptografię