Progress Sitefinity 9.1 has XSS via file upload, because JavaScript code in an HTML file has the same origin as the application's own code. This is fixed in 10.1.
References
Link | Resource |
---|---|
https://www.sec-consult.com/en/blog/advisories/multiple-vulnerabilities-in-progress-sitefinity/index.html | Exploit Third Party Advisory |
https://packetstormsecurity.com/files/143894/Progress-Sitefinity-9.1-XSS-Session-Management-Open-Redirect.html | Exploit Third Party Advisory VDB Entry |
Configurations
Information
Published : 2018-02-12 06:29
Updated : 2018-03-05 11:03
NVD link : CVE-2017-18176
Mitre link : CVE-2017-18176
JSON object : View
CWE
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Products Affected
progress
- sitefinity