CVE-2023-6784: Potential Use of the Sitefinity System for Distribution of Phishing Emails

4.7 CVSS

Description

A malicious user could potentially use the Sitefinity system for the distribution of phishing emails.

Classification

CVE ID: CVE-2023-6784

CVSS Base Severity: MEDIUM

CVSS Base Score: 4.7

Affected Products

Vendor: Progress Software Corporation

Product: Sitefinity

Exploit Prediction Scoring System (EPSS)

EPSS Score: 0.08% (probability of being exploited)

EPSS Percentile: 35.16% (scored less or equal to compared to others)

EPSS Date: 2025-02-03 (when was this score calculated)

References

https://www.progress.com/sitefinity-cms
https://community.progress.com/s/article/Sitefinity-Security-Advisory-for-Addressing-Security-Vulnerability-CVE-2023-6784-December-2023

Timeline