QID 378670
Date Published: 2023-08-09
QID 378670: Progress OpenEdge Uniform Resource Locator (URL) Injection Vulnerability.
Accelerate Application Development with the Progress OpenEdge Integrated Development Environment.
products
Affected Version
Progress OpenEdge prior to 11.7.16
Progress OpenEdge 12.0.0 to 12.2.11
Progress OpenEdge 12.3.0 to 12.6.0
QID Detection Logic (Authenticated):
This QID checks for the file vulnerable version of Progress OpenEdge
On succeessful exploitation it allows remote attackers to perform a URL injection attack to change identity or role membership.
Solution
Upgrade to latest version of OpenEdge.Refer to OpenEdge for details.
Vendor References
CVEs related to QID 378670
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| Progress OpenEdge |
|