LiveActive security incident?Get immediate response
CVE Record

CVE-2017-18179: Progress Sitefinity 9.1 uses wrap_access_token as a non-expiring authentication token that remains valid af...

Progress Sitefinity 9.1 uses wrap_access_token as a non-expiring authentication token that remains valid after a password change or a session termination. Also, it is transmitted as a GET parameter. This is fixed in 10.1.

UnknownCVSS not scoredNot KEV-listedUpdated
Glexia's TakeAutomated analysishigh

Security readout for executives and security teams

Plain-English summary

Progress Sitefinity 9.1 handled a URL-carried access token as if it were a long-lived password. Changing a user password or ending a session did not invalidate that token. If exposed, it could allow continued access until the product is fixed or upgraded.

Executive priority

Prioritize remediation for internet-facing or business-critical Sitefinity 9.1 sites. The issue affects account access control, and normal response actions like password change or session termination may not be sufficient until fixed.

Technical view

CVE-2017-18179 concerns Sitefinity 9.1 wrap_access_token behavior: the token does not expire after password changes or session termination and is transmitted as a GET parameter. The CVE description states this is fixed in Sitefinity 10.1. No CVSS, CWE, or detailed affected CPE data is supplied.

Likely exposure

Organizations running Progress Sitefinity 9.1 are the relevant exposure group. Risk is higher where Sitefinity is internet-facing or where URLs may be retained in logs, browser history, monitoring tools, proxies, or referrer data.

Exploitation context

The supplied bundle does not show CISA KEV listing or cited evidence of active exploitation. The practical risk is token persistence: password resets and session termination may not remove access if a valid wrap_access_token has already been exposed.

Researcher notes

Evidence is specific but limited: the bundle names Sitefinity 9.1, the wrap_access_token behavior, GET transmission, and fix in 10.1. It does not provide CVSS, CWE, CPEs, exploit telemetry, or detailed vendor remediation steps beyond the fixed version.

Mitigation direction

  • Upgrade affected Sitefinity 9.1 deployments to 10.1 or later per vendor fix statement.
  • Check Progress guidance for supported remediation on older or customized deployments.
  • Treat exposed URL tokens as credentials and review related logs and access paths.
  • Reduce token leakage by limiting sensitive URL retention in logs and analytics.

Validation and detection

  • Inventory Sitefinity versions and confirm whether any deployment is version 9.1.
  • Review authentication flows for wrap_access_token use in URLs.
  • Confirm password changes and session termination invalidate comparable tokens after remediation.
  • Check logs and monitoring systems for historical token exposure indicators.
Prepared
Confidence
medium
Sources
4

Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.

Potential ATT&CK relevance

Conservative CVE-to-ATT&CK context

These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.

ATT&CK lookup starting points

Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.

description · low confidence lookup

Credential and access behavior lookup

The CVE wording references authentication or credential exposure, so valid-account and credential-access review may help. This is a Glexia inferred lookup path, not an official MITRE, ATT&CK, or CVE Program mapping.

Open ATT&CK lookup
cve · low confidence lookup

CVE-2017-18179 mapping review

Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.

Open ATT&CK lookup
Vulnerability profileCVE Program record
Severity
Unknown
CVSS
Not scored
Known Exploited
No
Published
Official CVE source material

CNA and ADP enrichment extracted from CVE v5

These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.

0CVSS vectors
0Timeline events
0ADP providers
3Source links

CVSS and timeline data

No CVSS vectors or timeline events were available in the normalized CVE source material.

Affected products

Products and packages named in the record

VendorProductVersion / packageStatus
n/an/an/aListed
Weakness

CWE details

No CWE listed

CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.