First published: Mon Feb 12 2018(Updated: )
Progress Sitefinity 9.1 has XSS via the Last name, First name, and About fields on the New User Creation Page. This is fixed in 10.1.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Progress Sitefinity | =9.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-18177 is a vulnerability in Progress Sitefinity 9.1 that allows cross-site scripting (XSS) attacks via the Last name, First name, and About fields on the New User Creation Page.
The severity of CVE-2017-18177 is medium with a CVSS score of 5.4.
To fix CVE-2017-18177, update Progress Sitefinity to version 10.1 or higher.
Yes, you can find additional information about CVE-2017-18177 at the following references: [Link 1](https://packetstormsecurity.com/files/143894/Progress-Sitefinity-9.1-XSS-Session-Management-Open-Redirect.html), [Link 2](https://www.sec-consult.com/en/blog/advisories/multiple-vulnerabilities-in-progress-sitefinity/index.html).
The CWE ID for CVE-2017-18177 is CWE-79, which refers to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting').