CVE-2018-17055: Malicious File Upload
Published Sep 28, 2018
·Updated
An arbitrary file upload vulnerability in Progress Sitefinity CMS versions 4.0 through 11.0 related to image uploads.
Affected Software
1 affected component
Progress Sitefinity>=4.0<=11.0
Event History
Sep 28, 2018
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Frequently Asked Questions
1
What is the vulnerability ID for this arbitrary file upload vulnerability in Progress Sitefinity CMS?
The vulnerability ID is CVE-2018-17055.
2
What is the severity of the CVE-2018-17055 vulnerability?
The severity of the CVE-2018-17055 vulnerability is high with a severity value of 7.5.
3
Which versions of Progress Sitefinity CMS are affected by CVE-2018-17055?
Progress Sitefinity CMS versions 4.0 through 11.0 are affected by CVE-2018-17055.
4
What is the CWE (Common Weakness Enumeration) ID associated with CVE-2018-17055?
The CWE ID associated with CVE-2018-17055 is CWE-434.
5
How can I fix the arbitrary file upload vulnerability in Progress Sitefinity CMS?
To fix the arbitrary file upload vulnerability in Progress Sitefinity CMS, apply the security patches provided by the vendor and update to a non-vulnerable version.