CWE-20: Improper Input Validation in web services in Progress Sitefinity
Summary
| CVE | CVE-2026-7195 |
|---|---|
| State | PUBLISHED |
| Assigner | ProgressSoftware |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2026-06-02 14:17:14 UTC |
| Updated | 2026-06-02 14:48:39 UTC |
| Description | CWE-20: Improper Input Validation in web services in Progress Sitefinity 14.1.x through 14.3.x, 14.4.x before 14.4.8152, 15.0.x before 15.0.8234, 15.1.x before 15.1.8335, 15.2.x before 15.2.8441, 15.3.x before 15.3.8531, and 15.4.x before 15.4.8630 allows a remote unauthenticated attacker to compromise the integrity and confidentiality of user accounts. Successful exploitation requires user interaction and a non-default site configuration. |
Risk And Classification
Primary CVSS: v3.1 8.8 HIGH from [email protected]
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Problem Types: CWE-20 | CWE-20 CWE-20: Improper Input Validation
| Version | Source | Type | Score | Severity | Vector |
|---|---|---|---|---|---|
| 3.1 | [email protected] | Secondary | 8.8 | HIGH | CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
| 3.1 | CNA | CVSS | 8.8 | HIGH | CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
CVSS v3.1 Breakdown
Attack Vector
NetworkAttack Complexity
LowPrivileges Required
NoneUser Interaction
RequiredScope
UnchangedConfidentiality
HighIntegrity
HighAvailability
HighCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|---|---|---|---|
| CNA | Progress Software | Sitefinity | affected 14.1.0 14.4.0 custom | Not specified |
| CNA | Progress Software | Sitefinity | affected 14.4.8100 14.4.8152 custom | Not specified |
| CNA | Progress Software | Sitefinity | affected 15.0.8200 15.0.8234 custom | Not specified |
| CNA | Progress Software | Sitefinity | affected 15.1.8300 15.1.8335 custom | Not specified |
| CNA | Progress Software | Sitefinity | affected 15.2.8400 15.2.8441 custom | Not specified |
| CNA | Progress Software | Sitefinity | affected 15.3.8500 15.3.8531 custom | Not specified |
| CNA | Progress Software | Sitefinity | affected 15.4.8600 15.4.8630 custom | Not specified |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| community.progress.com/s/article/Sitefinity-Security-Advisory-for-Addressing-Securit... | [email protected] | community.progress.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.