# CVE-2024-11625

## Summary

- **CVE ID:** CVE-2024-11625
- **Severity:** HIGH
- **CVSS Score:** 7.7 (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:L)
- **CWE:** CWE-209
- **Published:** Jan 7, 2025
- **Last Modified:** Mar 13, 2026

## Description

Information Exposure Through an Error Message vulnerability in Progress Software Corporation Sitefinity.This issue affects Sitefinity: from 4.0 through 14.4.8142, from 15.0.8200 through 15.0.8229, from 15.1.8300 through 15.1.8327, from 15.2.8400 through 15.2.8421.

## Affected Products

- Progress Software Corporation — Sitefinity (4.0)
- Progress Software Corporation — Sitefinity (15.0.8200)
- Progress Software Corporation — Sitefinity (15.1.8300)
- Progress Software Corporation — Sitefinity (15.2.8400)

## References

- [CNA](https://www.progress.com/sitefinity-cms)
- [CNA](https://community.progress.com/s/article/Sitefinity-Security-Advisory-for-Addressing-Security-Vulnerabilities-CVE-2024-11625-and-CVE-2024-11626-January-2025)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.30%
- **EPSS Percentile:** 22.3

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-17._