CVE-2017-18175: XSS
Progress Sitefinity 9.1 has XSS via the Content Management Template Configuration (aka Templateconfiguration), as demonstrated by the src attribute of an IMG element. This is fixed in 10.1.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2017-18175?
CVE-2017-18175 is a vulnerability in Progress Sitefinity 9.1 that allows for cross-site scripting (XSS) attacks via the Content Management Template Configuration.
How does CVE-2017-18175 affect Progress Sitefinity 9.1?
CVE-2017-18175 affects Progress Sitefinity 9.1 by allowing an attacker to perform XSS attacks through the src attribute of an IMG element.
What is the severity of CVE-2017-18175?
The severity of CVE-2017-18175 is medium, with a severity value of 5.4.
How can I fix CVE-2017-18175?
To fix CVE-2017-18175, upgrade Progress Sitefinity to version 10.1 which includes a fix for this vulnerability.
Where can I find more information about CVE-2017-18175?
You can find more information about CVE-2017-18175 at the following references: [Link 1](https://packetstormsecurity.com/files/143894/Progress-Sitefinity-9.1-XSS-Session-Management-Open-Redirect.html) and [Link 2](https://www.sec-consult.com/en/blog/advisories/multiple-vulnerabilities-in-progress-sitefinity/index.html).