CVE-2026-7313 Details
Description
CWE‑522: Insufficiently Protected Credentials in web services in Progress Sitefinity version from 8.0.5700 to 13.3.7652 allows a remote authenticated attacker to obtain plain-text credentials used connect to Sitefinity Insight service. Successful exploitation requires active integration with Sitefinity Insight, non-default site configuration and valid back-end authorization.
A vulnerability allowing remote authenticated attackers to obtain plain-text credentials used to connect to the Sitefinity Insight service has been identified in Progress Sitefinity. This issue affects versions 8.0.5700 prior to 13.3.7652. The vulnerability arises from insufficient protection of credentials in web services, specifically in ServiceStack web services. Successful exploitation requires active integration with Sitefinity Insight, non-default site configuration, and valid back-end authorization.
Progress Sitefinity has released product updates for all supported versions. Users are advised to update to the latest version, which is 15.4.8631. For instructions on how to apply the update, refer to the Progress Sitefinity Knowledge Base Article on updating Sitefinity.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jun 2, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-522 | Insufficiently Protected Credentials | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| progress sitefinity | >= 8.0.5700, < 13.3.7652 |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 22, 2026 | CVE Translated | [email protected] |
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jun 4, 2026 | Initial Analysis | [email protected] |
| Jun 2, 2026 | New CVE Received | [email protected] |