First published: Mon Feb 12 2018(Updated: )
Progress Sitefinity 9.1 has XSS via the Content Management Template Configuration (aka Templateconfiguration), as demonstrated by the src attribute of an IMG element. This is fixed in 10.1.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Progress Sitefinity | =9.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-18175 is a vulnerability in Progress Sitefinity 9.1 that allows for cross-site scripting (XSS) attacks via the Content Management Template Configuration.
CVE-2017-18175 affects Progress Sitefinity 9.1 by allowing an attacker to perform XSS attacks through the src attribute of an IMG element.
The severity of CVE-2017-18175 is medium, with a severity value of 5.4.
To fix CVE-2017-18175, upgrade Progress Sitefinity to version 10.1 which includes a fix for this vulnerability.
You can find more information about CVE-2017-18175 at the following references: [Link 1](https://packetstormsecurity.com/files/143894/Progress-Sitefinity-9.1-XSS-Session-Management-Open-Redirect.html) and [Link 2](https://www.sec-consult.com/en/blog/advisories/multiple-vulnerabilities-in-progress-sitefinity/index.html).