CVE Radar Logo
CVERadar
CVE Radar Logo
CVERadar

CVE-2024-1632

Medium Severity
Progress
SVRS
30/100

CVSSv3
6.5/10

EPSS
0.01687/1

CVE-2024-1632 is a Sitefinity vulnerability allowing low-privileged users to access sensitive information within the administrative backend. This information disclosure vulnerability, while having a moderate CVSS score of 6.5, has a SOCRadar Vulnerability Risk Score (SVRS) of 30, indicating a lower immediate risk compared to critical vulnerabilities. However, the presence of the "In The Wild" tag means that attackers are already exploiting it. Successful exploitation could expose confidential data, potentially leading to further compromise or data breaches. While not requiring immediate patching based solely on its SVRS, administrators should still address CVE-2024-1632 promptly to mitigate the risk of unauthorized data access. The vulnerability stems from improper access control (CWE-284), permitting low-privileged users to bypass security measures. Timely patching is crucial to prevent malicious actors from leveraging this vulnerability to gain unauthorized access to sensitive information.

In The Wild
CVSS:3.1
AV:N
AC:L
PR:L
UI:N
S:U
C:H
I:N
A:N
2024-02-28

2024-12-16

Indicators of Compromise

No IOCs found for this CVE

Exploits

No exploits found for this CVE

Enhance Your CVE Management with SOCRadar Vulnerability Intelligence
Get comprehensive CVE details, real-time notifications, and proactive threat management all in one platform.
CVE Details
Access comprehensive CVE information instantly
Real-time Tracking
Subscribe to CVEs and get instant updates
Exploit Analysis
Monitor related APT groups and threats
IOC Tracking
Analyze and track CVE-related IOCs

News

CVE-2024-1632 | Progress Sitefinity prior 13.3.7649/14.4.8135/15.0.8227 Administrative Area access control
vuldb.com2024-12-16
CVE-2024-1632 | Progress Sitefinity prior 13.3.7649/14.4.8135/15.0.8227 Administrative Area access control | A vulnerability classified as critical has been found in Progress Sitefinity. This affects an unknown part of the component Administrative Area. The manipulation leads to improper access controls. This vulnerability is uniquely identified as CVE-2024-1632. It is possible to initiate the attack remotely. There is no exploit available. It is
vuldb.com
rss
forum
news

Social Media

No tweets found for this CVE

Affected Software

Configuration 1
TypeVendorProduct
AppProgresssitefinity

References

ReferenceLink
[email protected]https://community.progress.com/s/article/Sitefinity-Security-Advisory-for-Addressing-Security-Vulnerabilities-CVE-2024-1632-and-CVE-2024-1636-February-2024
[email protected]https://www.progress.com/sitefinity-cms
AF854A3A-2127-422B-91AE-364DA2661108https://community.progress.com/s/article/Sitefinity-Security-Advisory-for-Addressing-Security-Vulnerabilities-CVE-2024-1632-and-CVE-2024-1636-February-2024
AF854A3A-2127-422B-91AE-364DA2661108https://www.progress.com/sitefinity-cms
[email protected]https://community.progress.com/s/article/Sitefinity-Security-Advisory-for-Addressing-Security-Vulnerabilities-CVE-2024-1632-and-CVE-2024-1636-February-2024
[email protected]https://www.progress.com/sitefinity-cms

CWE Details

CWE IDCWE NameDescription
CWE-284Improper Access ControlThe software does not restrict or incorrectly restricts access to a resource from an unauthorized actor.

CVE Radar

Real-time CVE Intelligence & Vulnerability Management Platform

CVE Radar provides comprehensive vulnerability intelligence by monitoring CVE databases, security advisories, and threat feeds. Get instant updates on new vulnerabilities, exploit details, and mitigation strategies specific to your assets.

Get Free Vulnerability Intelligence AccessAccess real-time CVE monitoring, exploit analysis, and threat intelligence