Progress Sitefinity 9.1 has XSS via file upload, because JavaScript code in an HTML file has the same origin as the application's own code. This is fixed in 10.1.
References
Link | Resource |
---|---|
https://packetstormsecurity.com/files/143894/Progress-Sitefinity-9.1-XSS-Session-Management-Open-Redirect.html | Exploit Third Party Advisory VDB Entry |
https://www.sec-consult.com/en/blog/advisories/multiple-vulnerabilities-in-progress-sitefinity/index.html | Exploit Third Party Advisory |
History
No history.
MITRE Information
Status: PUBLISHED
Assigner: mitre
Published: 2022-10-03T16:23:15
Updated: 2022-10-03T16:23:15
Reserved: 2022-10-03T00:00:00
Link: CVE-2017-18176
JSON object: View
NVD Information
Status : Analyzed
Published: 2018-02-12T14:29:00.270
Modified: 2018-03-05T19:03:27.893
Link: CVE-2017-18176
JSON object: View
Redhat Information
No data.
CWE