// For flags

CVE-2025-1968

 

Severity Score

7.7
*CVSS v3.1

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

0
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

Track*
*SSVC
Descriptions

Insufficient Session Expiration vulnerability in Progress Software Corporation Sitefinity under some specific and uncommon circumstances allows reusing Session IDs (Session Replay Attacks).This issue affects Sitefinity: from 14.0 through 14.3, from 14.4 before 14.4.8145, from 15.0 before 15.0.8231, from 15.1 before 15.1.8332, from 15.2 before 15.2.8429.

*Credits: N/A
CVSS Scores
Attack Vector
Network
Attack Complexity
High
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
Low
Attack Vector
Network
Attack Complexity
High
Authentication
None
Confidentiality
Complete
Integrity
Complete
Availability
Partial
* Common Vulnerability Scoring System
SSVC
  • Decision:Track*
Exploitation
None
Automatable
No
Tech. Impact
Total
* Organization's Worst-case Scenario
Timeline
  • 2025-03-04 CVE Reserved
  • 2025-04-09 CVE Published
  • 2025-04-10 CVE Updated
  • 2025-04-10 EPSS Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
  • ---------- First Exploit
CWE
  • CWE-613: Insufficient Session Expiration
CAPEC
  • CAPEC-60: Reusing Session IDs (aka Session Replay)
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Progress Software Corporation
Search vendor "Progress Software Corporation"
Sitefinity
Search vendor "Progress Software Corporation" for product "Sitefinity"
>= 14.0 <= 14.3
Search vendor "Progress Software Corporation" for product "Sitefinity" and version " >= 14.0 <= 14.3"
en
Affected
Progress Software Corporation
Search vendor "Progress Software Corporation"
Sitefinity
Search vendor "Progress Software Corporation" for product "Sitefinity"
>= 14.4.0 < 14.4.8145
Search vendor "Progress Software Corporation" for product "Sitefinity" and version " >= 14.4.0 < 14.4.8145"
en
Affected
Progress Software Corporation
Search vendor "Progress Software Corporation"
Sitefinity
Search vendor "Progress Software Corporation" for product "Sitefinity"
>= 15.0.0 < 15.0.8231
Search vendor "Progress Software Corporation" for product "Sitefinity" and version " >= 15.0.0 < 15.0.8231"
en
Affected
Progress Software Corporation
Search vendor "Progress Software Corporation"
Sitefinity
Search vendor "Progress Software Corporation" for product "Sitefinity"
>= 15.1.0 < 15.1.8332
Search vendor "Progress Software Corporation" for product "Sitefinity" and version " >= 15.1.0 < 15.1.8332"
en
Affected
Progress Software Corporation
Search vendor "Progress Software Corporation"
Sitefinity
Search vendor "Progress Software Corporation" for product "Sitefinity"
>= 15.2.0 < 15.2.8429
Search vendor "Progress Software Corporation" for product "Sitefinity" and version " >= 15.2.0 < 15.2.8429"
en
Affected