CVE-2017-18176: XSS
Progress Sitefinity 9.1 has XSS via file upload, because JavaScript code in an HTML file has the same origin as the application's own code. This is fixed in 10.1.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2017-18176?
CVE-2017-18176 is a vulnerability in Progress Sitefinity version 9.1 that allows XSS attacks through file upload.
How does CVE-2017-18176 work?
CVE-2017-18176 works by allowing JavaScript code in an HTML file to have the same origin as the application's own code, enabling XSS attacks.
How severe is CVE-2017-18176?
CVE-2017-18176 has a severity level of 5.4, which is considered medium.
How can I fix CVE-2017-18176?
To fix CVE-2017-18176, you should update to Progress Sitefinity version 10.1, where this vulnerability is fixed.
Is there any additional information about CVE-2017-18176?
Yes, you can find more information about CVE-2017-18176 in the following references: [Reference 1](https://packetstormsecurity.com/files/143894/Progress-Sitefinity-9.1-XSS-Session-Management-Open-Redirect.html), [Reference 2](https://www.sec-consult.com/en/blog/advisories/multiple-vulnerabilities-in-progress-sitefinity/index.html).