ZeroHour

CVE-2017-18175

PoC ×2
CVSS 3.0
5.4 medium
EPSS
<1%p51
Published
()
Modified
Description

Progress Sitefinity 9.1 has XSS via the Content Management Template Configuration (aka Templateconfiguration), as demonstrated by the src attribute of an IMG element. This is fixed in 10.1.

Vendors
progress
Products
sitefinity
Weakness
CWE-79
Vector
CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

In the news

No ingested article mentions this CVE yet.