CVE detail
CVE-2019-7215 — CVE-2019-7215
Published 2019-06-06 · Modified 2026-06-17 · Vendor progress · Product sitefinity · Source nvd
MEDIUM
severity
CVSS-derived band
0.0104
EPSS probability
exploitation probability, 30d
61.0%
EPSS percentile
percentile vs all CVEs
NOT LISTED
CISA KEV
known exploited catalog
Description
Progress Sitefinity 10.1.6536 does not invalidate session cookies upon logouts. It instead tries to overwrite the cookie in the browser, but it remains valid on the server side. This means the cookie can be reused to maintain access to the account, even if the account credentials and permissions are changed.
Remediation
No vendor-published fix data in our corpus for this CVE. Check the references below or the vendor's PSIRT / security advisories page.
References