CVE-2023-6784
Potential Use of the Sitefinity System for Distribution of Phishing Emails
Severity Score
4.3
*CVSS v3.1
Exploit Likelihood
*EPSS
Affected Versions
*CPE
Public Exploits
0
*Multiple Sources
Exploited in Wild
-
*KEV
Decision
Track
*SSVC
Descriptions
A malicious user could potentially use the Sitefinity system for the distribution of phishing emails.
Un usuario malintencionado podría utilizar el sistema Sitefinity para la distribución de correos electrónicos de phishing.
*Credits:
N/A
CVSS Scores
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
Attack Vector
Attack Complexity
Authentication
Confidentiality
Integrity
Availability
* Common Vulnerability Scoring System
SSVC
- Decision:Track
Exploitation
Automatable
Tech. Impact
* Organization's Worst-case Scenario
Timeline
- 2023-12-13 CVE Reserved
- 2023-12-20 CVE Published
- 2024-11-27 CVE Updated
- 2025-03-30 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-20: Improper Input Validation
CAPEC
- CAPEC-98: Phishing
- CAPEC-163: Spear Phishing
References (2)
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Progress Search vendor "Progress" | Sitefinity Search vendor "Progress" for product "Sitefinity" | >= 4.0 < 13.3.7648 Search vendor "Progress" for product "Sitefinity" and version " >= 4.0 < 13.3.7648" | - |
Affected
| ||||||
Progress Search vendor "Progress" | Sitefinity Search vendor "Progress" for product "Sitefinity" | >= 14.1 < 14.1.7828 Search vendor "Progress" for product "Sitefinity" and version " >= 14.1 < 14.1.7828" | - |
Affected
| ||||||
Progress Search vendor "Progress" | Sitefinity Search vendor "Progress" for product "Sitefinity" | >= 14.2 < 14.2.7932 Search vendor "Progress" for product "Sitefinity" and version " >= 14.2 < 14.2.7932" | - |
Affected
| ||||||
Progress Search vendor "Progress" | Sitefinity Search vendor "Progress" for product "Sitefinity" | >= 14.3 < 14.3.8029 Search vendor "Progress" for product "Sitefinity" and version " >= 14.3 < 14.3.8029" | - |
Affected
| ||||||
Progress Search vendor "Progress" | Sitefinity Search vendor "Progress" for product "Sitefinity" | >= 14.4 < 14.4.8133 Search vendor "Progress" for product "Sitefinity" and version " >= 14.4 < 14.4.8133" | - |
Affected
| ||||||
Progress Search vendor "Progress" | Sitefinity Search vendor "Progress" for product "Sitefinity" | >= 15.0 < 15.0.8223 Search vendor "Progress" for product "Sitefinity" and version " >= 15.0 < 15.0.8223" | - |
Affected
|