8.7
/ 10
HIGH
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:N
Description
CWE‑522: Insufficiently Protected Credentials in web services in Progress Sitefinity version from 8.0.5700 to 13.3.7652 allows a remote authenticated attacker to obtain plain-text credentials used connect to Sitefinity Insight service. Successful exploitation requires active integration with Sitefinity Insight, non-default site configuration and valid back-end authorization.
AI Analysis
Insufficiently protected credentials vulnerability in Progress Sitefinity, allowing remote authenticated attackers to obtain plain-text credentials for the Sitefinity Insight service.
Basic Information
ID
CVE-2026-7313
Source
ProgressSoftware
Published
Jun 2, 2026 at 13:09
Affected Product
Vendor
Progress Software
Product
Sitefinity
Version
8.0.5700 to 13.3.7652
Affected Versions
Progress Software Sitefinity 8.0.5700
CWE Classification
AI Assessment
AI Score
8.7 / 10
AI Severity
High
Vendor
Progress Software
Product
Sitefinity
Version
8.0.5700 to 13.3.7652